Computing.Net > Forums > Windows 95/98 > Virus/Trojan/Dialer hi jack Problem

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Virus/Trojan/Dialer hi jack Problem

Reply to Message Icon

Name: Willby
Date: April 14, 2005 at 16:47:01 Pacific
OS: win95 Plus
CPU/Ram: Intel 150
Comment:

The system is an old IBM Aptiva running Win 95.

My son was using it when it started to dial out to the inter-net. He could not stop it. Every time that he canceled it, it would start to dial up.

He tried to Shut down by using START Shut Down, but the system would not shut down. Instead, a popup came up that said system not responding shut down yes/no.

Clicking on shut down caused the popup to disappear and instantly reappear.

Finally he shut the power off and restarted the system. And immediately the following was displayed:
SECURITY WARNING

A fatal error has occurred at 00281C0011E66 in VXD VMN(01) + 00010E36. Error was caused by Trojan-Spy,HTML.SmitFraud.c


* System can not function in normal mode.
Please check your security settings.

* Scan your PC with any available antivirus/spyware remover to fix the [problem.

And it started dialing out, and

Also there were several new Icons on the desk top for Porn sites that he could not remove. He turned off power and restarted

I picked up the PC and took it home with me and was able to remove the programs and Icons that were added using add/remove programs.

I tried to run an antivirus from the CD drive but the system could not see it, so I moved it to a floppy and tried to run it from there. It started to run but I could not initiate a scan.

I still can not shut it down using START – shutdown.


I am able to do some things id SAFEMODE




Sponsored Link
Ads by Google

Response Number 1
Name: DAVEINCAPS
Date: April 14, 2005 at 18:47:20 Pacific
Reply:

There are fewer malware detectors for 95 than more recent OS versions. I don't think adaware SE will work. This page describes another detector, spybot, and links to a FAQ about getting it to run in 95. There's also a link to download it.

It looks like a 4 meg file. I suppose you could burn it to a cd, boot up the laptop with a bootdisk and copy the file to it from the cd.

Others may post in with knowledge of detectors that also run in 95.

Whenever your computer starts to dial out, it's best to disconnect the modem. I got a $40 phone bill once due to a game site that claimed they had my permission to install their software. I finally got the phone company to remove the charge as they'd had similar complaints.


0

Response Number 2
Name: Derek
Date: April 14, 2005 at 20:22:13 Pacific
Reply:

Check out this free Trojan finder/fixer:

A2FREE - JUST DOWN PAGE

The website seems to have gone down right now so I can't check whether it is suitable for Win95.

Derek.W


0

Response Number 3
Name: jboy
Date: April 16, 2005 at 09:16:19 Pacific
Reply:

Ad-Aware SE Personal Edition in Win 95

Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.


0

Response Number 4
Name: Derek
Date: April 16, 2005 at 11:31:45 Pacific
Reply:

That link to A2FREE now works. It might or might not happen to work with W95 but, as you probably found out, this is not claimed.

Derek.W


0

Response Number 5
Name: Derek
Date: April 16, 2005 at 11:33:57 Pacific
Reply:

On second thoughts best avoid A2FREE. It might well find the problems but if it tries to fix W98 style you could get into a mess.

Derek.W


0

Related Posts

See More



Response Number 6
Name: mmmoohya
Date: April 17, 2005 at 02:04:48 Pacific
Reply:

these seem to be quite good solutions. They work with xp bat can work with win95, too, with little changes:
1) Kill task "wp.exe"
2) Delete "C:\wp.exe" - You will also see a file called "C:\wp.bmp". This is the image you see on desktop (the blue screen)
3) Delete all registry entries with "wp.exe" in them
4) Uninstall SecurityIGuard (some security, this is the wolves guarding the henhouse)
5) Fix registry settings to allow control panel tabs to be visible:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"WallpaperStyle"=dword:00000000
"NoDispBackgroundPage"=dword:00000000

I am able now to change wallpaper by overwriting all entries in registry that display "c:\wp.bmp" with my own specified wallpaper. However, the "Browse" button in the control panel applet on the Desktop tab is disabled - preventing the changing of wallpaper directly.
*******************************
If your familiar with working with the registry it is quite simple to activate the missing tabs on control panel. The following keys (if present) must have their values changed to 0 (hex) or deleted.

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System

NoDispBackgroundPage
NoDispSettingsPage
NoDispScrSavPage
NoDispAppearancePage

Note that although this will allow you to display the tabs, changing the wallpaper is still not possible as the "Browse" functionality to change the wallpaper on the "Desktop" tab (XP) is disabled. I am still trying to figure this one out.

If your really desperate to change the wallpaper you have two options:

1) Search the registry for all instances of "c:\wp.bmp" and instead point it to your own wallpaper file.
2) Delete file "C:\wp.bmp" then place your own file in root of C: and name it "wp.bmp"

I will post when I figure out the browse problem.

EDIT: Its not just the "Browse" functionality that is borked. Every direct way (that I know of) to set the wallpaper without going through the registry is disabled.
**************************************************

Welcome to the forum.

IMPORTANT you need to Move HijackThis to a permanent folder for the important backup feature to work properly.

To do this:

Go to My Computer (Windows key E ), double click on C:
Click File > New > Folder

Name it HijackThis and unzip/move or download the program again to this folder.

Then :-

Rerun HJT,and put a tick beside these :-


O4 - HKLM\..\Run: [Messenger] C:\WINDOWS\System32\msgrsv32.exe
O4 - HKCU\..\Run: [WindowsFY] c:\wp.exe

now close all windows and browsers and click FIX CHECKED

then reboot and post a fresh Hijackthis log
********************************

cancellare i wp poi
You could try running the System File Checker (sfc.exe), this will scan all protected Windows files to verify their versions have not been overwritten or damaged, and if so will replace the compromised version with a fresh copy.

To run it, click Start/Run and type 'sfc.exe /scannow' (without the quotes but with the space between the 'e' and the '/').

Alternatively, you can click start/Run and type in CMD and click O.K., when the black window opens type in "sfc /scannow".

You will need to insert your Windows CD into the drive to enable sfc to effect the repair.


mmmoohya


0

Response Number 7
Name: jboy
Date: April 17, 2005 at 08:22:22 Pacific
Reply:

.. the hell??

SFC is not (never has been) part of Win95

Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.


0

Response Number 8
Name: Willby
Date: April 17, 2005 at 10:37:57 Pacific
Reply:

Thankyou for all of the info. I did not have much luck, soooo!!!! I finally bit the bullet and used the system restore disk that came with the system and of course all of the programs and data not on the restore disk were removed.

I have installed an antivirus/worm program; however it will not execute. It says that it can not find MFC42.DLL.

I have downloaded an MFC42.DLL but do not know how to install it.

I can find .DLL 's but they are not all in the same place in the system.

How do I install the DLL and where do I install the DLL??

Thanks,

Willby


0

Response Number 9
Name: jboy
Date: April 17, 2005 at 15:53:20 Pacific
Reply:

Have you tried \windows\system ?? Seems like a logical place - just copy the file. You may find that others are also needed.

Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.


0

Response Number 10
Name: jboy
Date: April 17, 2005 at 16:02:46 Pacific
Reply:

If you do discover that you need the rest of the MFC library files, try here

Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.


0

Response Number 11
Name: Dan BW
Date: April 19, 2005 at 22:11:45 Pacific
Reply:

I'm a techi, I had this on a machine today, this is how I fixed it. partially from mmmh***'s post.

1) Kill task "wp.exe"
2) Delete "C:\wp.exe" - You will also see a file called "C:\wp.bmp". This is the image you see on desktop (the blue screen)
3) Delete all registry entries with "wp.exe" in them
4) Uninstall SecurityIGuard (some security, this is the wolves guarding the henhouse)
5) Fix registry settings to allow control panel tabs to be visible:

*****Heres the difference and also the fix****

Where the original post says set to 0. Don't.
Back up your registry for safety.
Delete the "System" key.[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
It will allow you to change your background and enable browsing etc of wall paper.



0

Response Number 12
Name: jboy
Date: April 20, 2005 at 14:33:50 Pacific
Reply:

.. the hell? Is that even an answer to this question?

Kind of moot - system's been restored.

Ah, 'techis'

Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.


0

Response Number 13
Name: Dan BW
Date: April 26, 2005 at 20:13:24 Pacific
Reply:

Indeed it is the fix, I've had 3 systems this week come in with that trojan/malware.
give it ago.


0

Response Number 14
Name: JAMESWICKS
Date: May 11, 2005 at 08:41:43 Pacific
Reply:

Hi, i had the SMITFRAUD trojan on my computer and got my screensaver to work without going through the steps shown. HOWEVER now im really screwed. Everytime i reboot my system crashes just as it starts to put icons on my desktop. What i have to do is CTRL+ALT+DLT and stop loads of stuff happening on my computer. This eventually allows me access to my PC. But then when i go on the internet in my favourites are loads of S**T about free porn etc. and my homepage is redirected. Any help is welcomed but i am new to using forums and am not familiar with accessing my registry or using "Hijacker" etc so be easy with me.


0

Response Number 15
Name: DAVEINCAPS
Date: May 11, 2005 at 12:08:15 Pacific
Reply:

I mentioned in the last post here:

http://computing.net/windows95/wwwboard/forum/165296.html

how I got rid of smithfraud.

Sounds like you have a bunch of other stuff too. You need to download adaware SE personal and run it. Be sure to download the most recent update when first running it.

If you can't get it to boot normally, perhaps restoring a previous registry will help. Bootup the computer. Before the OS starts loading, start tapping the F8 key. A menu should come up. Choose 'command prompt only'. At the prompt type scanreg/restore and enter. Choose a registry to restore with a date that precedes the problem.


0

Response Number 16
Name: dowhitt
Date: May 25, 2005 at 06:16:55 Pacific
Reply:

To fix the disabled background setting in display properties I did this: open any .bmp in paint. Save it, then choose "Set As Background" from the file menu. After your wallpaper has been changed, the background changing area will no longer be disabled.


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows 95/98 Forum Home


Sponsored links

Ads by Google


Results for: Virus/Trojan/Dialer hi jack Problem

Possible WinMX virus/trojan? www.computing.net/answers/windows-95/possible-winmx-virustrojan/136045.html

trojan horse virus caused problems. www.computing.net/answers/windows-95/trojan-horse-virus-caused-problems/145913.html

Help Please trojans adaware www.computing.net/answers/windows-95/help-please-trojans-adaware/162116.html