Link to home
Start Free TrialLog in
Avatar of aaron63
aaron63

asked on

Smitfraud virus plus disabled task manager plus no desktop icons and no start menu

Not sure where I picked up this virus, but I got one of those 'a Trojan has been detected on this computer' message boxes. Being an idiot I fell for it and ended up paying $20 for some bogus spyware remover program. But unfortunately it didn't end there.

I restarted with the plan to start in Safe Mode so I could get a real spyware remover program working. When I restarted, however, the desktop is blank and there is no Start menu. Furthermore when I push Cntrl-Alt-Delete I get the following message: Task manager has been disabled by your administrator.

Same problem whether I am in Safe Mode or not.

So what steps do I need to do to dig myself out of this hole? Obviously I can't surf or install anything with the computer in question (since there is no desktop and no start menu), but I can use my laptop to download the needed files to a floppy/CD and hopefully run something that way.

Thanks for any help.
Avatar of rpggamergirl
rpggamergirl
Flag of Australia image

http://www.kellys-korner-xp.com/regs_edits/taskmanager.reg
Download and run the above regfile to enable the task manager, then download and run Smitfraudfix.


Please download SmitfraudFix:
http://siri.geekstogo.com/SmitfraudFix.php
Extract the content (a folder named SmitfraudFix) to your Desktop.
Next, please reboot your computer in Safe Mode by rebooting the computer,
and repeatedly tapping the F8 key as the pc starts. Choose "Safe Mode" from
the options listed.
 
Once in Safe Mode, open the SmitfraudFix folder again and double-click
smitfraudfix.cmd
 
Select option #2 - Clean by typing 2 and press "Enter" to delete infected
files.
 
You will be prompted : "Registry cleaning - Do you want to clean the
registry?" answer "Yes" by typing Y and press "Enter" in order to remove
the Desktop background and clean registry keys associated with the
infection.
 
The tool will now check if wininet.dll is infected. You may be prompted to
replace the infected file (if found); answer "Yes" by typing Y and press
"Enter".
 
The tool may need to restart your computer to finish the cleaning process;
if it doesn't, please restart it into Normal Windows.
A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.
The report can also be found at the root of the system drive, usually at C:\rapport.txt


Later on when you can run Hijackthis and show us the log please.
http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis

Open Hijackthis, click "Do a system scan and save a logfile" please don't fix anything yet.
Once your task manager is enabled, you should be able to run explorer.exe via task manager > New Task > explorer.exe
And your desktop should return.

Hi,

Is it windows xp home or prof

Ded9
Avatar of aaron63
aaron63

ASKER

It is XP Home.

rpggamergirl:

How do I download and run taskmanager.reg without a desktop? Should I download it with another computer and put it on a floppy?

Thanks.
Avatar of aaron63

ASKER

Okay I ran the regedit and the smitfraudfix through command prompt in safe mode. I now get my desktop back, but I'm obviously still infected. Here is my logfile from hijackthis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:12:47 PM, on 1/1/2008
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\lpcywinp.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\igbjpjoa.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Network Monitor\netmon.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\QuickTime\qttask    .exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73 .exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray .exe
C:\PROGRA~1\LEXMAR~1\ACMonitor_X73 .exe
C:\PROGRA~1\NORTON~1\navapw32 .exe
C:\WINDOWS\mrofinu1053.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD .exe
C:\WINDOWS\System32\regsvr32.exe
C:\Program Files\QuickTime\qttask     .exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched .exe
C:\Program Files\Spyware Doctor\swdoctor .exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt .exe
C:\Program Files\QdrModule\QdrModule11.exe
C:\Program Files\QdrPack\QdrPack11.exe
C:\WINDOWS\mrofinu1053 .exe
C:\Program Files\Common Files\W?nSxS\w?auclt.exe
C:\Program Files\WinAble\winable.exe
C:\Program Files\Router\Router.exe
C:\Program Files\Spyware Doctor\swdoctor  .exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent .exe
C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
C:\Program Files\QdrModule\QdrModule11 .exe
C:\Program Files\Router\Router .exe
C:\Program Files\QdrPack\QdrPack11 .exe
C:\Program Files\WinAble\winable .exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Spyware Doctor\Update.exe
C:\Program Files\Internet Explorer\iexplore.exe
H:\HiJackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
F3 - REG:win.ini: load=C:\WINDOWS\System32\awvtu.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\lpcywinp.exe,C:\WINDOWS\system32\userinit.exe
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Lexmark X73 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
O4 - HKLM\..\Run: [Lexmark X73 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask     .exe" -atboottime
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu1053.exe 61A847B5BBF72813329E3B466188719AB689201522886B092CBD44BD8689220221DD3257
O4 - HKLM\..\Run: [lingruvu] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\lingruvu.dll"
O4 - HKLM\..\Run: [drmsrv32] C:\DOCUME~1\CYNTHI~1\LOCALS~1\Temp\ssmmt.exe
O4 - HKLM\..\Run: [WinPerformance] C:\Program Files\WinPerformance\WinPerformance.lnk
O4 - HKLM\..\Run: [a00f10b1] rundll32.exe "C:\WINDOWS\System32\jnajwjgm.dll",b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor  .exe" /Q
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_0
O4 - HKCU\..\Run: [QdrModule11] "C:\Program Files\QdrModule\QdrModule11.exe"
O4 - HKCU\..\Run: [QdrPack11] "C:\Program Files\QdrPack\QdrPack11.exe"
O4 - HKCU\..\Run: [Thza] "C:\Program Files\Common Files\W?nSxS\w?auclt.exe"
O4 - HKCU\..\Run: [WinAble] C:\Program Files\WinAble\winable.exe
O4 - HKCU\..\Run: [Router] C:\Program Files\Router\Router.exe
O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'Default user')
O4 - S-1-5-18 Startup: Camio Viewer 3.2.lnk = C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Camio Viewer 3.2.lnk = C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe (User 'Default user')
O4 - Startup: Camio Viewer 3.2.lnk = C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15012/CTSUEng.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-12.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1093143268257
O16 - DPF: {C68F9105-04FD-4B48-B6CC-2A076F711C35} (HpodPCFileCtrl2 Class) - file://E:\MEMDISC\ALBUM_A\VIEW\PLUGIN\HPODPCFC.CAB
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15012/CTPID.cab
O18 - Filter hijack: text/html - {07851C6A-1C43-41d9-8319-BC89154A8C00} - C:\Program Files\RcvSystem\httpdchk.dll
O20 - AppInit_DLLs: NVDESK32.DLL c:\windows\system32\ldcore.dll
O21 - SSODL: AOL Instant Messenger - {850D130D-99CA-A18A-E8D2-92D6BEC16BD6} - c:\program files\aim\mzjecx32.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: DomainService -   - C:\WINDOWS\System32\igbjpjoa.exe
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

--
End of file - 10229 bytes
rpg and aaron63:

This is a VERY badly infected machine.

Hope you don't mind if I interject. I have a feeling (hopefully I'm wrong but I've worked a few of these over the past couple of days) that this is the new file infecting Vundo Trojan (ya Vundo wasn't nasty enough already was it?).

Many of the entries are very similar to a log I'm working right now at WhatTheTech. The file infector infects mainly all the startups (04's). Combofix will remove the infected files but the programs will not run any more. sUBs has come through yet again with another tool to help with this. I would suggest first to hit this with SDFix to deal with some of the backdoors, then combofix, then a CFScript, then new tool if needed. This one is bad. One question...aaron63:, have you been using cracks here? That's where these nasties are coming from.

Here's what I suggest:

Please download SDFix and save it to your Desktop.
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe 

You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Double click on SDFix.exe. It should automatically extract a folder called SDFix to your system drive (usually C:\). Please reboot your computer in Safe Mode by doing the following :
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, a menu with options should appear;
Select the first option, to run Windows in Safe Mode, then press "Enter".
Choose your usual account.

Open the SDFix folder and double click on RunThis.bat to start the script.
Type Y and press Enter to begin the script.
It will start cleaning your PC and then prompt you to press any key to Reboot.
Press any key to restart the PC.
Your system will take longer than normal to restart as the fixtool will be removing files.
When the desktop loads the Fixtool will complete the removal and display Finished.
Press any key to end the script and to load your desktop icons.

A text file should automatically open,
Please upload the log at EE-Stuff.com
Use the link below and login using your Experts-Exchange username and password.
http://www.ee-stuff.com
Click on "Expert Area" tab
type or paste the link to your Question
"Browse" your pc to the location of your SDFix log and click "Upload"
Copy the resulting "url" and post it back here.

-------------------------------------------------------

Download and Run ComboFix (by sUBs)

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Disable your Anti-virus and any real-time Anti-spyware monitors that are running.
Then double click Combofix.exe & follow the prompts.
When finished, it will produce a log for you. Upload that log in your next reply with a new HijackThis log.  
Please upload the log at EE-Stuff.com
Use the link below and login using your Experts-Exchange username and password.
http://www.ee-stuff.com
Click on "Expert Area" tab
Type or paste the link to your Question
"Browse" your pc to the location of your combofix log and click "Upload"
Copy the resulting "url" and post it back here.

Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall.
Note 2: Remember to re-enable your Anti-virus and Anti-spyware.

NOTE: If you have issues connecting to your network or internet after running combofix you can either simply reboot, or do the following:
* Going to Control Panel > Network Connections.
* Right click on their Network icons & select "Repair"
or
Alternately, if the Network icon appears in the notification area in the lower right corner of Desktop, right-click it, and then click Repair from the shortcut menu.

PLEASE ALSO NOTE: Combofix will typically fix most and sometimes all Malware entries but many times a script is also needed to finish cleaning up. So please keep CF until advised whether you need the script or not.




Avatar of aaron63

ASKER

IndiGenus-

I have a vague knowledge of what 'cracks' are but not really.I'm middle aged, and while I have a computer programming degree I'm waaay out of the loop with technology. I don't even have an IPOD! :) My computer hardware is so out of date it won't run the cool RPGs out there (which I find so tempting). So no, I haven't been using any 'cracks'.

 When all this happened I was surfing for news of the most recent UFC fight (to see the live results). I am a martial artist and had an unhealthy fascination with who won the matches. Google had revealed a number of sites offering live results and I was hitting refresh on these various websites. A lot of popups were coming off these websites as well. It probably wasn't a coincidence that this problem happened almost immediately after visiting all those sites.

I'm trying your solution now. I am forced to run safe-mode with command prompt because the desktop and start menu won't come up in safe mode. I ran SDFix and it rebooted. But it didn't bring up any logfile (or anything else for that matter) after it restarted. I did, however, ask it to restart in safe mode when it restarted. Wat that a mistake? Should I have just let it restart as normal?

Thanks for your help.
SOLUTION
Avatar of rpggamergirl
rpggamergirl
Flag of Australia image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of aaron63

ASKER

Thank you for your help. Both of you! Combofix worked. I had to run it like three times for it to finally get through, but it seems to have fixed it. I'll post the log file. Hopefully it will let me even after I submit this as finalized.
Avatar of aaron63

ASKER

Dang it all. I'm doing something wrong with uploading the log files. If you really need to see them I can post them in them here, but I don't want to waste the screen space.

Once again thanks for your help.
If you can't upload it, you can also just try and attach the logfile into "Attach Code Snippet' window.

You closed your question so quickly,  that's a contrast to Askers who close their question after 2 weeks or so, :)

Well, you have the vundo file infector there in your hijackthis logfile, we always want to look at a Combofix log because sometimes there are bad files that Combofix cannot remove during the first run where we have to use its CFScript function, the more so in your case having the file infector.
There's another tool you need to run to replace the deleted/infected legit files.

Combofix nuetralizes the infection, but doesn't restore the deleted files.
>>Combofix nuetralizes the infection, but doesn't restore the deleted files.<<
rephrase that..... Combofix nuetralizes the infection but won't replace/restore the legit files that has been deleted.
New version of CF 08-01-02.1 will now attempt to replace the infected files.
Yes I've been watching the cf discussion threads and wow....sUBs is doing some amazing stuff. Glad he's on our side...
Oh yeah, he's amazing! Fighting malware willl be difficult without his awesome tool.