A Little Computer help Please.....

Search
bucsfan67

bucsfan67

Pop-culture, entertainment, sports and contest Mod
Joined
Dec 20, 2002
Messages
33,977
Reaction score
5
OK guys, i know alot of you know alot more about computers than me, can u give me a little help?

Last night i start getting this little box on my desktop background saying


Security Warning
a fatal error in the IE has occurred at 0028:C0011E36 in VXD VMM<01) + 00010E36 Erro was caused by Trojan-Spy.HTML.Smitfraud.c

System cannot function in normal mode, please check security settings

Scan your PC now With Available antivirus/spyware applications to fix the problem






Ok, i ran Ad-aware, Spybot, and my AOL spyware, along with McAffee Antivirus.....of course each thing found a couple of things, and ridded them, and McAfee said it found 3 infected files, but deleted them all, and is clean....However, each time i restart, i still get this box....Is there anyway to get rid of this trojan thing, since i know its name?


Thanks for any advice.....Its greatly appreciated...
 
TTinCO

TTinCO

.
Joined
Sep 21, 2004
Messages
28,775
Reaction score
2
Yeah, sounds like you have a trojan. Re run your virus scanner & let me know the name of the virus\trojan that it finds.
 
bucsfan67

bucsfan67

Pop-culture, entertainment, sports and contest Mod
Joined
Dec 20, 2002
Messages
33,977
Reaction score
5
TTinCO said:
Yeah, sounds like you have a trojan. Re run your virus scanner & let me know the name of the virus\trojan that it finds.


isnt this the name of it TT?


Trojan-Spy.HTML.Smitfraud.c
 
wmublows

wmublows

..
Joined
Sep 21, 2004
Messages
1,007
Reaction score
1
I had that too and had to reinstall xp. I tried everything to get rid of it but couldn't. Good luck
 
coconutman

coconutman

New member
Joined
Oct 4, 2004
Messages
2,518
Reaction score
0
wmublows said:
I had that too and had to reinstall xp. I tried everything to get rid of it but couldn't. Good luck


That's not always a bad thing. It's good to format you comp once a while.
 
TTinCO

TTinCO

.
Joined
Sep 21, 2004
Messages
28,775
Reaction score
2
Also, stop the wp.exe process & then search for and delete the wp.exe file (Ideally before doing the steps above)
 
TTinCO

TTinCO

.
Joined
Sep 21, 2004
Messages
28,775
Reaction score
2
Hey Bucs, are you on MSN or AOL IM?
 
TTinCO

TTinCO

.
Joined
Sep 21, 2004
Messages
28,775
Reaction score
2
Here is the fix Bucs. You probably ought to print this out and be sure to follow these instruction EXACTLY.

Go to Start > Control Panel > Add or Remove Programs and remove the following programs, if found:

Security IGuard
Virtual Maid
Search Maid


Exit Add/Remove Programs.

*Click Here to download Killbox by Option^Explicit.
*Extract the program to your desktop and double-click on its folder, then double-click on Killbox.exe to start the program.
*In the killbox program, select the Delete on Reboot option.
*Copy the file names below to the clipboard by highlighting them and pressing Control-C:

C:\wp.exe
C:\wp.bmp
C:\bsw.exe
C:\WINDOWS\sites.ini
C:\WINDOWS\popuper.exe
C:\WINDOWS\system32\hhk.dll
C:\WINDOWS\System32\helper.exe
C:\WINDOWS\System32\intmonp.exe
C:\WINDOWS\System32\msmsgs.exe
C:\WINDOWS\System32\ole32vbs.exe
C:\WINDOWS\system32\msole32.exe
C:\WINDOWS\System32\shnlog.exe
C:\WINDOWS\System32\intmon.exe
C:\WINDOWS\System32\msmsgs.exe


*Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
*Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

While your computer is restarting, tap the F8 key continually until a menu appears. Use your up arrow key to highlight Safe Mode, then hit enter.

*IMPORTANT* Be sure you know how to VIEW HIDDEN FILES

Using Windows Explorer, delete the following (please do NOT try to find them by "search" because they will not show up that way)

FOLDERS to delete (in bold) if found:

C:\Program Files\Search Maid
C:\Program Files\Virtual Maid
C:\Windows\System32\Log Files
C:\Program Files\Security IGuard

Reboot into normal mode.

A registry file to undo most of the changes is available here:
http://metallica.geekstogo.com/smitfraud.reg
Doubleclick that file and confirm you want to merge it with the registry.

1.) Download the Hoster from HERE Press "Restore Original Hosts" and press "OK". Exit Program.

2.) Download: http://www.mvps.org/winhelp2002/DelDomains.inf
To use: right-click and select: Install (no need to restart)
Note: This will remove all entries in the "Trusted Zone" and "Ranges" also.

3.) Download, install, and run CleanUp!

4.) Run a virus scan. If you do not have an AV installed, use ActiveScan - Save the results from the scan!
 

Whoson1st

New member
Joined
Oct 3, 2004
Messages
3,741
Reaction score
0
Was this trojan gotten from an email or from downloading something ? Or any idea ?

knock-on-wood; McAfee seems to have kept me "safe"
 
TTinCO

TTinCO

.
Joined
Sep 21, 2004
Messages
28,775
Reaction score
2
I'm not 100% sure, but I suspect that this spreads over broadband (DSL\cable) circuits by doing port scans on all the computers on the network.

Just ANOTHER very, very good reason why everyone MUST have a firewall and real time virus scanner.
 

ZZZSpeedster

New member
Joined
Sep 25, 2004
Messages
3,057
Reaction score
0
Way to copy and paste exactly what I provided TTINCO!

lol

:)
 

Whoson1st

New member
Joined
Oct 3, 2004
Messages
3,741
Reaction score
0
TTinCO said:
Here is the fix Bucs. You probably ought to print this out and be sure to follow these instruction EXACTLY.

Go to Start > Control Panel > Add or Remove Programs and remove the following programs, if found:

Security IGuard
Virtual Maid
Search Maid


Exit Add/Remove Programs.

*Click Here to download Killbox by Option^Explicit.
*Extract the program to your desktop and double-click on its folder, then double-click on Killbox.exe to start the program.
*In the killbox program, select the Delete on Reboot option.
*Copy the file names below to the clipboard by highlighting them and pressing Control-C:

C:\wp.exe
C:\wp.bmp
C:\bsw.exe
C:\WINDOWS\sites.ini
C:\WINDOWS\popuper.exe
C:\WINDOWS\system32\hhk.dll
C:\WINDOWS\System32\helper.exe
C:\WINDOWS\System32\intmonp.exe
C:\WINDOWS\System32\msmsgs.exe
C:\WINDOWS\System32\ole32vbs.exe
C:\WINDOWS\system32\msole32.exe
C:\WINDOWS\System32\shnlog.exe
C:\WINDOWS\System32\intmon.exe
C:\WINDOWS\System32\msmsgs.exe


*Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
*Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

While your computer is restarting, tap the F8 key continually until a menu appears. Use your up arrow key to highlight Safe Mode, then hit enter.

*IMPORTANT* Be sure you know how to VIEW HIDDEN FILES

Using Windows Explorer, delete the following (please do NOT try to find them by "search" because they will not show up that way)

FOLDERS to delete (in bold) if found:

C:\Program Files\Search Maid
C:\Program Files\Virtual Maid
C:\Windows\System32\Log Files
C:\Program Files\Security IGuard

Reboot into normal mode.

A registry file to undo most of the changes is available here:
http://metallica.geekstogo.com/smitfraud.reg
Doubleclick that file and confirm you want to merge it with the registry.

1.) Download the Hoster from HERE Press "Restore Original Hosts" and press "OK". Exit Program.

2.) Download: http://www.mvps.org/winhelp2002/DelDomains.inf
To use: right-click and select: Install (no need to restart)
Note: This will remove all entries in the "Trusted Zone" and "Ranges" also.

3.) Download, install, and run CleanUp!

4.) Run a virus scan. If you do not have an AV installed, use ActiveScan - Save the results from the scan!

When i click in CleanUp --it says I don't have access-FORBIDDEN. (It lets me see the page for a couple seconds first)
 
TTinCO

TTinCO

.
Joined
Sep 21, 2004
Messages
28,775
Reaction score
2
You're right (sorry, I didn't check your links, I just did some google digging)

:lolBIG: :lolBIG: :lolBIG:
 

Whoson1st

New member
Joined
Oct 3, 2004
Messages
3,741
Reaction score
0
Hey Thanks--I like to check up on my installed spyware to see what's what now and then.
But whoever said it wasn't a bad thing to have to "reformat"--does not know me!!!!
I would loose some of my handicapping programs as I don't understand how to save then to a CD--I've tried it a couple times and --it doesn't work .
 
bucsfan67

bucsfan67

Pop-culture, entertainment, sports and contest Mod
Joined
Dec 20, 2002
Messages
33,977
Reaction score
5
thanks guys....

I printed those instructions and am going to try it here in a little bit after lunch...dont understand alot of this stuff, so i hope i do it right...LOL

I do have a firewall, and mcaffee antivirus, so not sure how i got it...

Did nothing out of the norm yesterday, but it popped up there last night...

Thanks for the tips again guys...
 

Forum statistics

Threads
1,142,003
Messages
13,926,496
Members
104,835
Latest member
Icemanram
The RX is the sports betting industry's leading information portal for bonuses, picks, and sportsbook reviews. Find the best deals offered by a sportsbook in your state and browse our free picks section.FacebookTwitterInstagramContact Usforum@therx.com