OT Computer Help Needed!

BigDavis75

Making a Comeback
Joined
Mar 23, 2005
Posts
4,359
Reaction score
1,447
Location
Amherst, MA
I just got an error message on my background that says my computer is infected with spyware/adware. It says the name is Trojan-Spy.HTML.smitfraud.c

A) Where do I go to get rid of the problem

B) What do I do?

Any help would be greatly appreciated.
 

Chaz

observationist
Joined
Mar 11, 2003
Posts
11,327
Reaction score
7
Location
Wandering the Universe
What program gave you that message?

Your Antivirus program or was it a pop-up (or pop-under) when browsing?
 

KingofCards

My Hero
LEGACY MEMBER
Joined
May 13, 2002
Posts
11,918
Reaction score
2
Get rid of your computer immediatly before it attacks your TV!
 

Chaz

observationist
Joined
Mar 11, 2003
Posts
11,327
Reaction score
7
Location
Wandering the Universe
Trojan-Spy.HTML.Smitfraud.c
Other versions: .a

Aliases
Trojan-Spy.HTML.Smitfraud.c (Kaspersky Lab) is also known as: Phish-BankFraud.eml.a (McAfee), Trojan Horse (Symantec), Trojan.Bankfraud (Doctor Web), HTML.Phishing.Bank-1 (ClamAV), Trj/Citifraud.A (Panda), HTML/Smithfraud.gen (Eset)
Detection added Feb 11 2005
Description added Jun 20 2005
Behavior TrojanSpy
Technical Details

This Trojan program utilizes spoofing technology. The Trojan is represented by a fake HTML page. It is used for stealing confidential information about clients of Smith Barney financial company (www.smithbarney.com).

It is sent by email as an important message from Smith Barney company with the following subject:

Smith Barney: Security Maintenance

In terms of functionality this version is almost identical to Trojan-Spy.HTML.Smitfraud.a. It differs from it only in email's sender address and address of fake Internet site.
 
OP
OP
BigDavis75

BigDavis75

Making a Comeback
Joined
Mar 23, 2005
Posts
4,359
Reaction score
1,447
Location
Amherst, MA
I just did a virus scan and located the Trojan Druogna and found the following information which matches my problem:



Virus Profile: Druogna

Risk Assessment - Home Users:Low - Corporate Users:LowDate Discovered:4/25/2005Date Added:4/25/2005Origin:UnknownLength:37876, 97032Type:TrojanSubType:Win32DAT Required:4476

Virus Characteristics

Detection was added to cover for a 32 bit PE file originally called "bsw.exe " , having a filesize of 37.876 bytes. The file is internally compressed with the cryptx and upx packers.

Upon execution it failed to work properly in our test environment.

It is supposed to drop a bitmap file in the root of the harddisk, c:\wp.bmp . This is a real bitmap file that's being used as a full background. The blue screen that's shown is a deceiving one mentioning a trojan spy smithfraud.c.

So this is not a true warning message upon a virus/trojan intercept, it's just a bitmap picture filling the complete screen with the wallpaper bitmap having the fake message painted in it.

It might also drop the file wldr.dll , having a filesize of 87.032 bytes. This file is internally compressed with shrink and upx.

Registry changes may me made under

  • ..\Software\Microsoft\Windows\CurrentVersion\Run "BlueScreen W@rning "
Indications of Infection

  • Presence of the files/filesizes as mentioned above
  • Fake blue screen bitmap covering the complete screen
Method of Infection

  • Manual execution of the binary starts the infection, there's no exploit associated with this file.

Removal Instructions

All Users :
Use current engine and DAT files for detection and removal.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

Additional Windows ME/XP removal considerations


Aliases

Adware/BlueScreenWa (Panda), TR/Agent.CT (H+BEDV), Trojan.Win32.Agent.ct (Kaspersky), Win32/Druogna.F!Trojan (CA eTrust)
 

ActingWild

Hall of Famer
Joined
Aug 10, 2002
Posts
1,474
Reaction score
66
From what I've read ad-aware (NOT adware but ad-aware by lavasoft) and spybot-search & destroy are very good free programs for cleaning your computer. One of those annoying spyware programs hijacked my computer (there's apparently some very very evil people out there that make loads of money by forcing your computer to go to different webpages). Anyway, those two programs cleaned it up pretty well for me.
 
OP
OP
BigDavis75

BigDavis75

Making a Comeback
Joined
Mar 23, 2005
Posts
4,359
Reaction score
1,447
Location
Amherst, MA
ActingWild said:
From what I've read ad-aware (NOT adware but ad-aware by lavasoft) and spybot-search & destroy are very good free programs for cleaning your computer. One of those annoying spyware programs hijacked my computer (there's apparently some very very evil people out there that make loads of money by forcing your computer to go to different webpages). Anyway, those two programs cleaned it up pretty well for me.

How about SpySheriff (http://www.spysheriff.com/dl.php), is it secure and what have you heard? Also, do you have links for those two programs?
 

Chaz

observationist
Joined
Mar 11, 2003
Posts
11,327
Reaction score
7
Location
Wandering the Universe
It sounds like your AV program found it.

Be wary and skeptical of anything that tells you you have spyware or viruses unless it is the AntiVirus program or Spyware program you knowingly installed on your system.

Do not install SpySheriff. Everything I can find says it is an infection rather than a cure.

I would recommend the Microsoft AntiSpyware program. It has worked very well for me on many computers.
The only problems I had with it were from corruption of windows from previous infection.
 

CQ

Recovered WoW-aholic
Supporting Member
Joined
Mar 24, 2004
Posts
6,527
Reaction score
0
Location
Peoria, AZ
SirChaz said:
It sounds like your AV program found it.

Be wary and skeptical of anything that tells you you have spyware or viruses unless it is the AntiVirus program or Spyware program you knowingly installed on your system.

Do not install SpySheriff. Everything I can find says it is an infection rather than a cure.

I would recommend the Microsoft AntiSpyware program. It has worked very well for me on many computers.
The only problems I had with it were from corruption of windows from previous infection.

We recently installed Microsoft AntiSpyware and so far, love it! No problems, works great!!!!!!!! :thumbup:
 

devilalum

Heavily Redacted
Joined
Jul 30, 2002
Posts
16,776
Reaction score
3,187
CQ said:
We recently installed Microsoft AntiSpyware and so far, love it! No problems, works great!!!!!!!! :thumbup:

This one took care of a problem on my wife's computer that the lavasoft program couldn't fix.
 
OP
OP
BigDavis75

BigDavis75

Making a Comeback
Joined
Mar 23, 2005
Posts
4,359
Reaction score
1,447
Location
Amherst, MA
I dowloaded the anti-spyware and it found like 16 things, i still am infected to some degreee thoguh, because it messes with my homepage and still trys to direct me to the SpySheriff.
 

Chaz

observationist
Joined
Mar 11, 2003
Posts
11,327
Reaction score
7
Location
Wandering the Universe
BigDavis75 said:
I dowloaded the anti-spyware and it found like 16 things, i still am infected to some degreee thoguh, because it messes with my homepage and still trys to direct me to the SpySheriff.


Boot to safe mode and run the AntiSpyware and virus scan again.

If you have WindowsXP you can find Safe Mode instructions here .
 
OP
OP
BigDavis75

BigDavis75

Making a Comeback
Joined
Mar 23, 2005
Posts
4,359
Reaction score
1,447
Location
Amherst, MA
SirChaz said:
Boot to safe mode and run the AntiSpyware and virus scan again.

If you have WindowsXP you can find Safe Mode instructions here .

I did that but my Internet is still directed to a strange homepage and my I nternet is running at a lower Kbps than normal.
 

john h

Registered User
LEGACY MEMBER
Joined
Sep 24, 2002
Posts
10,552
Reaction score
13
Location
Little Rock
KingofCards said:
Get rid of your computer immediatly before it attacks your TV!

Go to the middle of the house and get in a closet with your wife,children and pets until you hear the all clear.
 

Chaz

observationist
Joined
Mar 11, 2003
Posts
11,327
Reaction score
7
Location
Wandering the Universe
BigDavis75 said:
I did that but my Internet is still directed to a strange homepage and my I nternet is running at a lower Kbps than normal.


Sorry man, still having trouble? Did you remove all the threats in the AntiSpyware program?

In the MS AntiSpyware program go to advanced tools. Go to browser restore.
You can reset your homepage there. It is listed as start page. On the left is the current settings on the right is the default settings. Check the altered setting and click restore if the default is correct.

Also search for and download hijackthis. Post the scan result here or send me a PM with it and we can help clean up your browser that way.
 

Latest posts

Staff online

Members online

Forum statistics

Threads
552,851
Posts
5,403,451
Members
6,315
Latest member
SewingChick65
Top