Explorer.exe connecting out on 6666

Discussion in 'Malware Help (A Specialist Will Reply)' started by OBG, Mar 7, 2008.

  1. OBG

    OBG Private E-2

    I ran a netstat -b and noticed that iexplore.exe and Explorer.exe are connecting out to several sites (darkness.il.us.abjects.net, 209.8.255.52, 208.110.69.227) on tcp port 6666. I also see them connecting to img229.imageshack.us, 213.202.254.38.static.rdns-uclo.net on port 80. I ran Spybot S&D, Adaware, Symantec AV and some other tools and found nothing. I blocked those sites on our firewall and my explorer and iexplorer started crashing after a few seconds. Winlogon restarts explorer but it continuously crashes and restarts. I opened the firewall back up and the crashing problem went away. I can't find anything with these symptoms anywhere on the web. Has anybody ran into this before? Thanks in advance for any help.
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi


    Not come across that before especially linking to imagshack as its just an image host, so to double check their is not malware on your system I would suggest running the below guide and when finished, attaching the requested logs and one of out malware experts will review these logs and see if indeed its malware related.

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. OBG

    OBG Private E-2

    I downloaded and ran the things in the link. After all the rebooting it is still connecting out. I have been running a sniffer on port 6666 and I still see it trying every couple of minutes. I am send the logs you wanted and I also have a trace I will send on another reply. If you need more info please let me know. Thanks for looking at it.
     
    Last edited by a moderator: Mar 12, 2008
  4. OBG

    OBG Private E-2

    Here is the sniffer trace of the 6666 port traffic.
     
    Last edited by a moderator: Mar 12, 2008
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach the three requested logs. Until you attach them, there is nothing more that we can do for you.
     
  6. OBG

    OBG Private E-2

    Let me try it again. Thanks.

     

    Attached Files:

  7. OBG

    OBG Private E-2

    Here are a couple more files that might help. You will have to take the .txt off of the 6666.pcap.txt wireshark capture file. Thanks.

     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I strongly advise that you do not save files in your root user account folder like below. Move them someplace more secure if you need this.
    2007-09-18 15:34 722,176 ----a-w C:\Documents and Settings\jeffcoda\gotomypc_428.exe
    2007-07-24 14:24 630,784 ----a-w C:\Documents and Settings\jeffcoda\GoToAssist_chat2way__317_en.exe
    2007-02-20 21:18 3,167,744 ----a-w C:\Documents and Settings\jeffcoda\gosetup.exe

    Do you have any idea what the below files are for?
    Code:
    2008-03-10 16:59    270    --sh--r    C:\Documents and Settings\jeffcoda\p3pp0s_conf.dat
    2008-03-10 16:35    ---------    d-----w    C:\Documents and Settings\jeffcoda\Application Data\.purple
    2007-10-01 19:07    39    --sh--r    C:\Documents and Settings\LocalService\p3pp0s_conf.dat
    And did you make the below copy yourself for some reason?
    Code:
    2008-03-07 09:49 . 2007-06-13 06:23  1,033,216  --a------  C:\WINDOWS\Copy of explorer.exe


    Is the below part of your startup process required by your company?

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\0\0]
    "Script"=browser.bat


    Uninstall the below old versions of software:
    J2SE Development Kit 5.0 Update 12
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 12
    Java 2 Runtime Environment, SE v1.4.1_07


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O20 - AppInit_DLLs: wsg_32.dll

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.


    After clicking Fix, exit HJT.

    Now we need to use ComboFix issues.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\WINDOWS\system32\fz_32.dll
    C:\WINDOWS\system32\wsg_32.dll
    C:\WINDOWS\system32\tmp.reg
    
    Registry::
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\U]
    
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"=""
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. OBG

    OBG Private E-2

    Here is what I found -

    I moved the files you suggested to another folder.

    C:\Documents and Settings\jeffcoda\p3pp0s_conf.dat seems to be a problem. I renamed it to p3pp0s_conf.dat.bad and moved it.

    C:\Documents and Settings\jeffcoda\Application Data\.purple is a folder used by Pidgin (instant messenger) which I do use.

    C:\Documents and Settings\LocalService\p3pp0s_conf.dat also seems to be bad. I also renamed it to p3pp0s_conf.dat.bad2 and moved it. I am attaching these in a zip file so you can see the contents.

    I did create this file - C:\WINDOWS\Copy of explorer.exe.

    The following script is used by our agency. [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\0\0]
    "Script"=browser.bat

    The old versions of Java were removed.

    I got called away and when I came back and picked this back up I messed up and ran combofix before I ran analyse. I then ran analyse but O20 - AppInit_DLLs: wsg_32.dll was not in the list.

    I rebooted and installed the version of Java in the link.

    Then I ran Ccleaner.

    I am attaching the logs and the zip file. I have been letting it run for a while now and I see no more of the bad connections in netstat. It looks like that got it. Many thanks. I have never seen one like this before and have no idea where I might have picked it up..
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    I don't know if these were really problems or not. As long as everything you run works okay without them, then you probably don't need them anyway.

    You forgot to uninstall J2SE Runtime Environment 5.0 Update 12. Uninstall it now.

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds