PDA

View Full Version : Trojan-Spy.HTML.Smitfraud.c



Rachel
06-07-2005, 11:48 PM
Ok my aunt and uncle have this on there computer. When you sign on in any user name and even in safe mode it will display a trick backroud that says:

Security warning

A fatal error in IE has occured at 0028:C0011E36 in VXD VMM(01) + 00010E36. Error was caused by Trojan-Spy.HTML.Smitfraud.c

* System can not function in normal mode.
* Please check you security settings.
* Scan your PC with any avaliable antivirus / spyware remover program to fix the problem.

The problem is that that's all there is. No icons, no toolbars, no startmenu, no right click... just that background. I have been doing everything through taskmanger and cmd.exe. I ran Norton, Spybot, and Ad-aware SE but still no toolbar with the start menu.

Everywhere I go to try to get the toolbar back it tells me this:
In order to restore your desktop settings download the following reg file(thanks to Grinler at Bleeping computer) to your desktop by right clicking on the link, and selecting save as.

http://www.bleepingcomputer.com/files/reg/smitfraud.reg

Once it has downloaded, double-click on the smitfraud.reg file on your desktop and when it asks if you would like to merge the data, click on the Yes button.

Reboot your computer and you should now be able to change your desktop settings back to how you would like it. If your desktop still looks strange, go into your display properties and click on the Themes tab. Change the theme to Windows XP and you will now be using the default Windows XP settings. Then change them as you see fit.

But I can't figure out how to do that but even if I did, I dont think I could see it on the desktop to even do what it says. It's like everything is hidden.

PLEASE PLEASE HELP ME!!!!! :( *sad puppy dog face*

Zeus
06-08-2005, 12:12 AM
what you probably have is something that has replaced the explorer shell. Let me look into where the OS shell is located. I remember something similar to this a while back. Once you reset the shell, it seems to work correctly.

I would also (in safe mode) check in the registry under
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\
There you should see Run and RunOnce folders. check to make sure there is nothing wacky there. YOu are going to want to clear things out there before you do anything to prevent reinfection when you reboot.

Zeus
06-08-2005, 12:34 AM
you should be able to google just about everything there if you don't recognize it. If you don't find anything on it, you could also compare it to another computer. You just have to be careful what you remove :-)

Zeus
06-08-2005, 12:37 AM
BTW, I looked at the reg key it points you to, there is some stuff there I don't trust. Even if you could find it. I would not merge it with your registry. I think it is just further entrenching itself in your system.

Zeus
06-08-2005, 12:48 AM
Have you tried running "sfc /scannow" from the command line?

Zeus
06-08-2005, 01:06 AM
pm