[urq] Non-Audi Spyware Problems

Thatcher Hubbard thatcher.hubbard at gmail.com
Wed Jun 1 18:55:08 EDT 2005


I've seen this one a couple of times recently, it played hell with one
of my client's offices (he's still got NT4 on his machines).

If you Google it, you'll find a couple of articles on removing the
Trojan.  They are long, and somewhat involved, but read a couple of
them to make sure you get the idea and you should have no problems.

If the machine it's on is either Win2k or XP, install the MS
Anti-Spyware Beta.  I've been replacing Ad-Aware/Spybot with that
recently, and though I hate to admit it, it works really well.  Don't
do it on a machine with low amounts of RAM though, the sucker eats
about 35MB when the active agent is running.

On 6/1/05, CARDCONSYS at aol.com <CARDCONSYS at aol.com> wrote:
>        Please excuse the non Audi content but I know some list members are IT
> professionals and none of my local contacts have been able to help.
> Someone using one of our computers (XP and AOL) picked up something which we
> have been unable to eliminate with Adaware or Spybot. Everytime it boots up we
> get the desktop message below(verbatim with mistakes) and Internet Explorer
> gets cut-off frequently. Any one recognise it?
> 
>                                Security warning
>        A fatal error in IE has occurred at 0028:C0011E36 in VXD VMM(01) +
>        00010E36. Error was caused by Trojan-Spy.HTML.Smitfraud.c
> 
>        * System can not function in normal mode.
>          Please check you security settings.
> 
>        * Scan your PC with any avaliable antivirus / spyware remover
>          program to fix the problem.
> 
>        Martin Dapot
> _______________________________________________
> Audifans urq mailing list
> Send posts to: mailto:urq at audifans.com
> Manage your list connection: http://www.audifans.com/mailman/listinfo/urq
> Have an urq question?  Check the Audifans Knowledgebase!
> http://www.audi-quattro.org/cgi-bin/twiki/view/Audi/UrQuattro
> Have an urq answer? ... Please help others by adding to the KB ... all contributions welcome!
>


More information about the urq mailing list