Re: Trojan

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 05/17/05


Date: Mon, 16 May 2005 20:28:37 -0400

From: "Teri" <Teri@discussions.microsoft.com>

| I have this message right in the center of my screen that says "A fatal error
| in IE has occured at 0028:C0011E36 in VXD VMM<01> + 00010F36. Error is
| caused by Trojan-Spy.HTML.Smitfraud.c
| * System cannot function in normal mode....."
| I think I have eliminated the Trojan with the help of Panda and Microsoft
| AntiSpyware BUT the message remains, my favorites folder is empty and in my
| control panel/DISPLAY I have only 2 tabs which is screen saver and settings.
| I ran Hijack This and everything there looked normal so what do I do next?

There are anti virus News Groups specifically for this type of discussion.

    microsoft.public.scripting.virus.discussion
    microsoft.public.security.virus
    alt.comp.virus
    alt.comp.anti-virus

I am curious as to what generated that error message. MS AS ? Panda ?

Trojan-Spy.HTML.Smitfraud.c

http://www.viruslist.com/en/viruses/encyclopedia?virusid=73615

Dump the contents of the IE Temporary Internet Folder cache (TIF)
Start --> Settings --> Control Panel --> Internet Options --> Delete Files

Dump the contents of the Mozilla FireFox Cache { if you use FireFox }
Tools --> Options --> Privacy --> Cache --> Clear

1) Download the TrendMicro Sysclean Front End

Download the utility SYSCLEAN_FE at the following URL --
http://www.ik-cs.com/got-a-virus.htm
SYSCLEAN_FE automates the download and execution process of the Trend Sysclean Package.
Direct URL --
http://www.ik-cs.com/programs/virtools/Sysclean_FE.exe

2) Download and install Ad-aware SE
        (free personal version v1.05)
        http://www.lavasoftusa.com/
        Update Ad-aware with the latest definitions and then exit the software.

3) Execute; SYSCLEAN_FE.EXE
        Choose; Unzip
        Choose; Close

        Execute; c:\sysclean\SYSCLEAN_FE.BAT
        { or Double-click on 'SYSCLEAN_FE Link' in c:\sysclean }
        when you get to the menu dhoose [1] so you can boot into Safe Mode.

4) Disable System Restore
        http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm

5) Reboot your PC into Safe Mode and shutdown as many applications as possible.

6) Execute; c:\sysclean\SYSCLEAN_FE.BAT
        { or Double-click on 'SYSCLEAN_FE Link' in c:\sysclean }
       Choose [2] on the menu and let SYCLEAN.COM scan your computer.
       when done, execute Ad-aware SE and perform a full scan of your PC and delete
       all objects found.

7) Restart your PC and perform a "final" Full Scan of your platform
       Execute; c:\sysclean\SYSCLEAN_FE.BAT
       { or Double-click on 'SYSCLEAN_FE Link' in c:\sysclean }
       Choose [2] on the menu and let SYCLEAN.COM scan your computer.
       when done, execute Ad-aware SE and perform a final scan of your PC and delete
       all objects found.

8) Re-enable System Restore and re-apply any System Restore preferences,
        (e.g. HD space to use suggested 400 ~ 600MB),

9) Reboot your PC.

10) Create a new Restore point

* * * Please report back your results * * *

-- 
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


Relevant Pages

  • Re: Nasty bugs
    ... Open a Command Prompt and execute; ... Then reboot. ... To find out if this has been installed on your PC, download HiJackThis! ... This will bring up the initial menu of choices and should be executed in Normal Mode. ...
    (microsoft.public.security.virus)
  • Re: virus - overtaken desktop
    ... Download the TrendMicro Sysclean Front End ... Execute; SYSCLEAN_FE.EXE ... If you are using WinME or WinXP, disable System Restore ... Reboot your PC into Safe Mode and shutdown as many applications as possible. ...
    (microsoft.public.security.virus)
  • Re: TV Media
    ... Download the TrendMicro Sysclean Front End ... Execute; SYSCLEAN_FE.EXE ... If you are using WinME or WinXP, disable System Restore ... Reboot your PC into Safe Mode and shutdown as many applications as possible. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: services.exe terminated unexpectedly with error code 128
    ... The machine will boot to the ... Download CLEAN.EXE from the URL -- ... Execute; CLEAN.EXE ... Reboot the PC into Safe Mode ...
    (microsoft.public.win2000.general)
  • Re: SP3 potential problem
    ... Enquire, plan and execute ... download the Net framework updates. ... Net Framework items from my machine. ...
    (microsoft.public.windowsxp.basics)