Trojan-Spy.HTML.Smit.fraud.c Please Help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by cubemb, Jul 17, 2005.

  1. cubemb

    cubemb Private E-2

    I've read up on all the recommended pages so far. But the problem is, is that this thing has stopped explorer from loading up.
    I get the message (0xc0000005) explorer.exe has failed to initialize.
    Now I can get access to firefox through the task manager and im running McAffee also through the same method but it doesnt seem to be helping.
    It wont let HJT run and im getting desperate, please help!

    Many thanks, Myles
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not being able to run explorer.exe is typcially related to other problems so you could have a bunch of issues to fix.

    I cannot tell from your wording whether you ran all of the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    If you have not then please complete them to the best of your ability.
    If you have, try to run the steps in message # 4 of the below thread. Some of the items may or may not apply to you because it is a somewhat generix fix for Smitfraud.

    http://forums.majorgeeks.com/showthread.php?p=611080#post611080
     
  3. cubemb

    cubemb Private E-2

    I've tried to go through these steps, however its as if there is a program on my computer which anticipates these moves, as some of the spyware removal tools cant even install, let alone run.
    Every time I try and run a program it stops as explorer.exe is constantly restarting every 2 seconds, causing any windows i've opened that second to shut. Adaware stops at the internet cache and doesnt go any further and im running out of ideas for solutions.
    Is there any information you require to help me more?
    Many thanks, Myles.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    While doing the steps, make sure you do not have any browsers open (except when running the online scanners) and stay disconnected from the Internet. Also look at the below.

    Try opening the application that you want to run and before scanning, first run Task Manager (click CTRL-ALT-DEL) and select Processes. Then use Task Manager to kill the explorer.exe process. This will cause your Desktop and icons to disappear. Leave Task Manager running. While doing your scans. To get your Desktop back, in TaskManager click File and select New Task (Run...) and enter explorer.exe and click OK.

    You can do this for each scan where necessary. For example, only have explorer.exe running in order to start the application (like Ad-Aware SE, Spybot, etc) and kill explorer.exe while running the scan.

    If you still have problems and cannot do this, follow the steps below from normal boot mode.

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
    Last edited: Jul 18, 2005
  5. cubemb

    cubemb Private E-2

    I've spent the best part of the day trying to get the scans to work but with only minimal luck. some have worked, others have diagnosed and frozen at the cleaning phase.
    Even in safe mode HJT just wont start and many of the other scanners are interupted by a process ddwin.exe.
    Is there anything you can suggest to cut around this problem?
    Cheers, Myles
     
  6. cubemb

    cubemb Private E-2

    sorry I lied, i didnt have the latest version of HJT. i've attached the log below.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you use DragonDictate speech recognition software ? ddwin.exe could be part of it.


    Bring up Control Panel and select Add/Remove programs and uninstall the below if found:
    PSGuard
    P2P Networking

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\system32\P2P Networking\P2P Networking.exe /AUTOSTART
    O4 - HKLM\..\Run: [PSGuard spyware remover] C:\Program Files\PSGuard\PSGuard.exe


    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\PSGuard <--- the whole folder
    C:\WINDOWS\system32\P2P Networking <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.


    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  8. cubemb

    cubemb Private E-2

    im on the stage of running CCleaner, but before I do, i've removed a file called 'intel32.exe' which is PSguard related thing and I figured out the file is actually dwwin.exe which is part of windows dr watson error reporting tool. now when i try and run Cleanmgr to delete all the temp files and recycle bin stuff, dwwin.exe crops up. would it be possible to move dwwin.exe to a safe folder to stop it from doin this until ive sorted the problem out, or would it cause big problems with windows?
    Thanks, Myles
     
  9. cubemb

    cubemb Private E-2

    Ok, after much investigating i've established that dwwin.exe is irrelevant as it simply notifies of an error, which doesnt actually show up. Whenever I try to run Cleanmgr.exe or CCleaner nothing happens and the dwwin.exe process starts and shuts. This leads me to believe there's a clever little virus type thing in one of the temp folders which is stopping these programs from working.
    I could quite possibly clean out these files manually but i dont know all of the directories and specifically that of the recycle bin so i can completely delete these files. forgive me if im talking rubbish, but thats just my limited understanding. Any ideas?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Do what I already asked in message # 7.

    Complete all the steps and post the follow up HJT log.
     
  11. cubemb

    cubemb Private E-2

    Ok. I've tried to follow the steps, however when I eventually got to the internet properties through the command line (desktop isnt functioning) and tried to clear out temp files and cookies, it came up with an error message relating to shell32.exe. Anyhow, here's the new HJT log. I gotta say this thing has me stumped.
    Cheers, Myles
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are having problems with your Desktop, go to the below thread and run step # 8:

    SpySheriff (aka SpywareNo) Removal

    Let me know if that helps.

    Also whenever you get error messages, you should always post the exact message (word for word).
     
  13. cubemb

    cubemb Private E-2

    Hi. Thank you kindly for all your help over the last week. I think im just going to surrender and reformat my computer and start afresh. I've tried so much but nothings helped :(
    Take care. Myles
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That should not be necessary but the decision is yours. We have fixed probably close to 100 of these SmitFraud problems; however, you seem to be having more problems than just that.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds