Smitfraud-C.CoreService, popups, others...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Skybax, Jun 13, 2007.

  1. Skybax

    Skybax Private E-2

    Hi,

    Just the other night while reading a forum I regularly visit, popups started to happen, a TAG (SearchUs) icon appeared on the desktop, Outerinfo appeared in the task bar, MS Office install window pops up, and a few others.

    I have AVG, SpywareBlaster, Spybot, AdAware and a few other tools on my PC. I keep up on my machine (updates) pretty good, use Firefox 99% of the time, use Gmail instead of Outlook Express, along with many other security measures. Seems like you need to be a rocket scientist these days just to have a decent machine... depressing.

    After running the scans Spybot detected 3 and was able to remove a few but the Smitfraud-C.CoreService remained. All of the symptoms are still happening about every 15 minutes or so. AdAware detected nothing. Panda detected 1 Virus, 37 Spyware, and 6 Hacking Tools/Rootkits. Hopefully somebody can help me, this is really bumming me out. Here are some logs...

    Panda Active Scan
    DSS Main
    DSS Extra
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You need to run our standard cleaning procedure and attach only the logs we request! However before getting to the standard cleaning procedure first do this.
    Now please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • the final VundoFix log
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use three messages to attach all of these logs!
     
  3. Skybax

    Skybax Private E-2

    Thanks for the reply.

    Thanks, I've been a member for years. :)

    Done.

    Done. Done. Yes. (Smitfraud, Vundo, TrojanDownloader, etc) No. No. Yes.

    Yes... same problems in my original post.

    Here are the first 3 logs, others will follows within minutes, thanks again.
     

    Attached Files:

  4. Skybax

    Skybax Private E-2

    Final logs... (see original post for Panda Activescan)
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note I don't recommend using Ad-Aware 2007. It is a massive resource hog that always has a service running even when you are not scanning. There is no need for this service to always be running.

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Also manually delete the below huge file which is wasting a ton of disk space (unless you know you need this file which I doubt).
    C:\272.tmp

    What is in the below folder? Do you know what this folder is for?
    C:\WINDOWS\system32\o02PrEz

    Now Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {475C3B2B-4075-4A31-8A0F-CF529A17D43E} - C:\WINDOWS\system32\mljjk.dll (file missing)
    O4 - HKLM\..\Run: [c2c145] C:\WINDOWS\c2c145
    O4 - HKLM\..\Run: [GPLv3] rundll32.exe "C:\WINDOWS\system32\phadtult.dll",realset
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - HKCU\..\Run: [dmcompos] C:\WINDOWS\system32\dmcompos.exe
    O4 - Startup: TA_Start.lnk = C:\Documents and Settings\Brian\Local Settings\Temp\TICHD003.exe

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  6. Skybax

    Skybax Private E-2

    Done. (used windows add/remove because CounterSpy didn't have an uninstall feature listed)

    When I went to delete those 2 files they were not there.

    Done.

    I don't know.

    Done.

    Done.

    Done.

    Done.

    Attached. (HJT will follow in the next posting within minutes)

    Popups have stopped.

    Question: There is a "Thumbs.db" file that appeared today on my desktop, it is also in every one of my desktop folders, it is transparent and has 2 gears on it, green & yellow. What is that?

    Question: I have been using "CleanUp!" for years, is "CCleaner" better?
     

    Attached Files:

  7. Skybax

    Skybax Private E-2

    HJT log.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is normal and it was always there. You just did not see it because you did not have viewing of hidden files enabled before. See this: http://en.wikipedia.org/wiki/Thumbs.db


    Yes we like Ccleaner more. But if you are happy with CleanUp then you should decide which you would like to use.


    Delete the below unknown folder:
    C:\WINDOWS\system32\o02PrEz

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  9. Skybax

    Skybax Private E-2

    Gotcha. Should I leave "show all hidden files/folders" on and leave the Thumbs.db icon alone on the desktop, or turn off?

    That was TrojanDownloader. When I went to delete it by highlighting it (not opening it) AVG warning window poped up detecting TrojanDownloader. I selected ignore, proceeded to delete the folder, then empty it from the Recycle Bin. That ok? (I was afraid by letting AVG take action it might wake it up or execute it)


    Done.

    Will do, many thanks.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's up to you. If you don't want to see hidden files & folders and file extensions then change things back to how they were. Just remember that doing so, also gives malware an easy hiding place.

    As stated, it's normal and was always there. If you disable viewing of hidden and system files you will not see it but it will still be there. You can disable caching of thumbnails (in the same place as viewing of hidden files is enabled/disabled) but you don't need to do this.


    Good! That is what I suspected it was.


    Surf safely!
     
  11. Skybax

    Skybax Private E-2

    Thanks again for the assistance, much appreciated.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome again! ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds