Trojan-Spy.HTML.Smitfraud.c HELP!, TrojanDownloader:Win32/Delf.FN problem!! |
Trojan-Spy.HTML.Smitfraud.c HELP!, TrojanDownloader:Win32/Delf.FN problem!! |
Jul 9 2005, 12:53 PM
Post
#1
|
|
|
New Member ![]() Posts: 1 OS: XP |
hi i'm just new here and i think i've got a virus problem of some sort. basically, my desktop screen is just all blue with some sort of captions written on with Trojan-Spy.HTML.Smitfraud.c on it. PLUS, i always get this windows explorer error pop up that everytime i click send or don't send.. the desktop seems to reset. my taskbar also doesn't seem to work eveytime the pop up pops up so i have to use alt+tab.. another thing.. i seem to have TrojanDownloader:Win32/Delf.FN on my computer as well. i need help please.
thanks in advance. here's my hijackthislog: Logfile of HijackThis v1.99.1 Scan saved at 2:25:56 PM, on 7/9/2005 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe C:\WINDOWS\vsnpstd2.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\WINDOWS\System32\intel32.exe C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe C:\WINDOWS\System32\n?tdde.exe C:\Program Files\succ\dode.exe C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe C:\Program Files\ewido\security suite\ewidoctrl.exe C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe C:\Program Files\LimeWire\LimeWire.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe C:\WINDOWS\System32\rundll32.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Mozilla Firefox\firefox.exe C:\DOCUME~1\xp\LOCALS~1\Temp\Rar$EX00.453\HijackThis.exe C:\WINDOWS\explorer.exe C:\WINDOWS\System32\imapi.exe C:\WINDOWS\System32\dwwin.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\xp\LOCALS~1\Temp\se.dll/spage.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\xp\LOCALS~1\Temp\se.dll/spage.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rogers.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn0\ycomp5_5_7_0.dll O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll O2 - BHO: (no name) - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\common\YIeTagBm.dll O2 - BHO: (no name) - {B17549A3-FF2B-484A-8586-0ED0A1C71B2C} - C:\WINDOWS\System32\kecp.dll O2 - BHO: (no name) - {CD8AE4EE-5B25-0BF7-07F6-51D058522295} - C:\WINDOWS\System32\bsk.dll O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - C:\Program Files\McAfee\McAfee VirusScan\VSCShellExtension.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn0\ycomp5_5_7_0.dll O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" O4 - HKLM\..\Run: [McAfee Guardian] "C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" /SU O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe O4 - HKLM\..\Run: [SNPSTD2] C:\WINDOWS\vsnpstd2.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\xp\LOCALS~1\Temp\se.dll,DllInstall O4 - HKLM\..\Run: [intel32.exe] C:\WINDOWS\System32\intel32.exe O4 - HKLM\..\Run: [PSGuard] C:\Program Files\PSGuard\PSGuard.exe O4 - HKCU\..\Run: [RHSI SHS] "C:\Program Files\Rogers\SelfHealing\SHS.exe" /background O4 - HKCU\..\Run: [Update Manager] "C:\Program Files\Rogers\Update Manager\UpdateManager.exe" /background O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR O4 - HKCU\..\Run: [Feem] C:\WINDOWS\System32\n?tdde.exe O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet O4 - HKCU\..\Run: [Rtnu] C:\Program Files\succ\dode.exe O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm O9 - Extra button: Yahoo! Services (HKLM) O9 - Extra button: Related (HKLM) O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM) O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper20041107.dll O16 - DPF: {3334504D-9980-0010-8000-00AA00389B71} - http://download.microsoft.com/download/0/C...C4D/mp43dmo.CAB O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by102fd.bay102.hotmail.msn.com/resources/MsnPUpld.cab O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsIns....cab?refid=4714 O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} (NPKCX Control) - http://gameguard1.levelupgames.ph/nProtect...Crypt/npkcx.cab O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab |
|
|
![]() |
Jul 9 2005, 01:13 PM
Post
#2
|
|
![]() retired HiJack Helper Posts: 5,080 From: The Netherlands, Europe OS: XP Home, XP Pro, Vista Home |
Welcome reckon to Geeks to Go!
HijackThis is running from a temporary folder. All backups will be lost then. Please create a new folder for it and place the program into that new folder. *** Please read these instructions carefully. You may want to print them. Copy the text to a Notepad file and save it to your desktop! Be sure to follow ALL instructions! During this advise we are making changes. If you cannot find some entrie, move on with the advise. *** Download SmitRem your desktop. Right click on the file and extract it to it's own folder on the desktop. *** Place a shortcut to Panda ActiveScan on your desktop. *** Please download the trial version of ewido security suite.
When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu". Launch ewido, there should be an icon on your desktop double-click it. The program will prompt you to update click the OK button The program will now go to the main screen
Click on Start Once the updates are installed, close Ewido for now. *** If you have not already installed Ad-Aware SE 1.06, please download and install AdAware SE 1.06. Check Here on how setup and use it - please make sure you update it first. *** Download about:buster by RubbeRDuckY. Update About:Buster
Download CWShredder. Update CWShredder
Download SpSeHjfix. Unzip SpSeHjfix to its own folder (ie c:\SpSeHjfix) *** Download and install CleanUp! Here Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu). Set the program up as follows: *Click "Options..." *Move the arrow down to "Custom CleanUp!" *Put a check next to the following:
Press the CleanUp! button to start the program. When it’s done, press Close. Reboot your computer into normal windows. *** Download the Killbox. Unzip it to the desktop Double-click Killbox.exe to run it. Select "Delete on Reboot". Place the following line (complete path) in bold in the "Full Path of File to Delete" box in Killbox: C:\Program Files\succ\dode.exe Put a mark next to "Delete on Reboot" Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt. If your computer does not restart automatically, please restart it manually. Reboot your computer in Safe Mode by doing the following: 1) Restart your computer 2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8. 3) Instead of Windows loading as normal, a menu should appear 4) Select the first option, to run Windows in Safe Mode. For additional help in booting into Safe Mode, see the following site: http://www.pchell.com/support/safemode.shtml *** Please run About:Buster:
*** Now run CWShredder. Click I Agree, then Fix and then Next, let it fix everything it asks about. *** Now run SpSeHjfix. A log will be saved in the same folder that you put the exe into. Please post the results of that log in your next reply. *** Open HijackThis Place a check against each of the following, making sure you get them all and not any others by mistake: R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\xp\LOCALS~1\Temp\se.dll/spage.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\xp\LOCALS~1\Temp\se.dll/spage.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank O2 - BHO: (no name) - {B17549A3-FF2B-484A-8586-0ED0A1C71B2C} - C:\WINDOWS\System32\kecp.dll O2 - BHO: (no name) - {CD8AE4EE-5B25-0BF7-07F6-51D058522295} - C:\WINDOWS\System32\bsk.dll O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\xp\LOCALS~1\Temp\se.dll,DllInstall O4 - HKLM\..\Run: [intel32.exe] C:\WINDOWS\System32\intel32.exe O4 - HKLM\..\Run: [PSGuard] C:\Program Files\PSGuard\PSGuard.exe O4 - HKCU\..\Run: [Feem] C:\WINDOWS\System32\n?tdde.exe O4 - HKCU\..\Run: [Rtnu] C:\Program Files\succ\dode.exe O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsIns....cab?refid=4714 Close all programs leaving only HijackThis running. Click on Fix Checked when finished and exit HijackThis. *** Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen. Wait for the tool to complete and disk cleanup to finish. The tool will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or partition where your operating system is installed. Post me the contents of the smitfiles.txt log as you post back. *** Open Ad-aware and do a full scan. Remove all it finds. *** Now open Ewido Security Suite:
* Click Complete System Scan and the scan will begin. * During the scan it will prompt you to clean files, click OK * When the scan is finished, look at the bottom of the screen and click the Save report button. * Save the report to your desktop *** Next go to Control Panel click Display > Desktop > Customize Desktop > Website > Uncheck "Security Info" if present. *** Reboot back into Windows and click the Panda ActiveScan shortcut, then do a full system scan. Make sure the autoclean box is checked! Save the scan log. *** After all that, please post back with how things went as well as the logs requested (Ewido, smitfiles, SpSeHjfix, About:Buster) and a new HiJackThis log. Good luck! EDIT: As there has been no reply from the original poster for more than two weeks this topic is now closed. If you are the original poster and still need assistance, please send me a PM. This post has been edited by g2i2r4: Jul 24 2005, 07:01 AM |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
5 / 490 | 10th May 2005 - 11:25 AM jamesjj started - last by Andy_veal |
|||||
![]() |
2 / 258 | 27th May 2005 - 01:12 AM daytonadman started - last by usetobe |
|||||
![]() |
10 / 1,737 | 12th July 2005 - 12:04 PM fortyozman started - last by usetobe |
|||||
![]() |
2 / 294 | 14th July 2005 - 04:33 AM TjDrifter24 started - last by TjDrifter24 |
|||||
|
Time is now: 24th November 2009 - 03:05 PM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising