Infeceted Smitfraud-c.gp then can not connect to internet

Discussion in 'Malware Help (A Specialist Will Reply)' started by pisitcom, Dec 20, 2008.

  1. pisitcom

    pisitcom Private E-2

    Infeceted Smitfraud-c.gp then can not connect to internet

    First of all, my english is not good ,sorry for any false in my post.
    There was a problem on PC running XP Pro 2002 SP2.

    1)At first the problem was that Internet Explorer(IE6) error and closed with system information like "...IE has encountered a problem and need close...".I did System Restore to the past few days then it worked normally for a while then error again.

    2)I installed SpyBot-Search & Destroy , scan (Check for problems) ,detected "Smitfraud-C.gp" ,then fixed. The problem still same that cannot connect to internet or connect for a while(ie. can connect to google,can search for some word, click a search result link then "the page can not be displayed")

    3)I used SmitfraudFix scan as suggested in "http://forums.majorgeeks.com/showthread.php?t=74265". Log created as attached : rapport_01 = search(safe mode), rapport_02 = clean(safe mode).The problem still occured.

    4)I performed "READ & RUN ME FIRST" as suggested in "http://forums.majorgeeks.com/showthread.php?t=35407". Logs created as attached (4 files).The problem still occured.

    5)At this moment there was some additinal faults
    -Some time after window boot finished "Windows Explorer has encountered a problem and needs to close." then it reflesh desktop. This will occure only one time after boot.
    -Some time when try to connect to internet TREND MICRO OfficeScan blocked the URL "_//hacel.com/np9.exe_" as attached pic.So I turn off System Restore and scan with TREND MICRO OfficeScan.It detected notthing.

    6)I also check for "Wireless Zero Configuration" it started and Automatic startup

    I use another PC to post this because the infected one still cannot connect to internet.
    I need help, please advise.
    Thanks in advance.
    Pisit
     

    Attached Files:

  2. pisitcom

    pisitcom Private E-2

    Additional attachments...

    Thanks
    Pisit
     

    Attached Files:

  3. pisitcom

    pisitcom Private E-2

    Last attachments...
    I think it importance.

    Thanks
    Pisit
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please do the below in the order written.

    • Run Malwarebytes and first select Update because you are out of date. Then run a full scan and attach the new log.
    • Uninstall the current version of SUPERAntiSpyware you now have installed. Then download and install this one SUPERAntiSpyware Make sure that you update the database during installation. Then run a new scan and also attach this log.
    Your MGlogs.zip file is very incomplete and this is going to stop me from creating a full fix. Did you get any error messages while running it? See the error messages mentioned in the Using MGtools link that was given and apply any fixes necessary.

    Also answer the below questions.

    Did you put the below file here? The valid MSN Messenger does not belong here.
    Code:
    2008-12-19 01:15 5,955 ----a-w C:\msnmsngr.exe
    Do you know what the below are and why they have dates for 541 yrs in the future?
     
    Last edited: Dec 23, 2008
  5. pisitcom

    pisitcom Private E-2

    Thanks for your time and sorry for some lately due to my mistake using MGTools.I forgot to place mgtools.exe to c:\ but run it from other folder.I fixed it and this time it run OK.

    As mentioned in first post the infected PC cannot connect to internet so I download all update via another PC and install to the infected one.I think this will be OK.

    New logs for Malwarebytes, SuperAntiSpyware and MGtools as attached.

    And the answer for your questions

    2008-12-19 01:15 5,955 ----a-w C:\msnmsngr.exe
    I don't know this.And I think nobody around my place can do something like this.

    c:\documents and settings\All Users\Start Menu\Programs\Startup\ARDV.lnk
    c:\program files\Trackerx90\Anti Removable Disk Virus (ARDV) by Trackerx90\ardv32.exe [2550-05-21 172099]
    This is safe(I think) program for protect PC from thumbdrive virus.I install this program in many PC with no issues.It made by thai people so the century is thai(2550=2007).

    R2 io.sys;IO.DLL Driver;\??\c:\windows\system32\drivers\io.sys [2550-10-20 5152]
    I don't know this.

    Thanks you
    Pisit
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but that does not explain why other things you are installing are using incorrect dates. Examples from your logs:
    Code:
    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    ARDV.lnk - c:\program files\Trackerx90\Anti Removable Disk Virus (ARDV) by Trackerx90\ardv32.exe [2550-05-21 172099]
    Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2544-02-13 83360]
    Orbit.lnk - c:\program files\Orbitdownloader\orbitdm.exe [2551-11-10 1690824]
    Utility Tray.lnk - c:\windows\system32\sistray.exe [2547-10-29 335872]
     
    R1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2551-12-04 8944]
    R1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2551-12-04 55024]
    R2 io.sys;IO.DLL Driver;\??\c:\windows\system32\drivers\io.sys [2550-10-20 5152]
    R2 TmFilter;Trend Micro Filter;\??\c:\program files\Trend Micro\OfficeScan Client\TmXPFlt.sys [2551-06-16 205328]
    R2 TmPreFilter;Trend Micro PreFilter;\??\c:\program files\Trend Micro\OfficeScan Client\TmPreFlt.sys [2551-06-16 36368]
    R3 DFE528TX;D-Link DFE-528TX PCI Adapter;c:\windows\system32\DRIVERS\DLKRTL.SYS [2551-11-06 45568]
    R3 SASENUM;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS [2551-12-04 7408]
    Notice that SUPERAntiSpyware is 2551 and sistray.exe is 2547. Your clock is also set to use the Thai calendar (at least right now). Is that what you wanted? Some of your dates on files are set this way and some are not.


    I'm not seeing any major problems. Let's fix take care of a few things and collect some additional info.


    Is the below something you configured and require?

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
    O23 - Service: VMwareService - Unknown owner - C:\WINDOWS\system\VMwareService.exe

    After clicking Fix, exit HJT.



    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Administrator\Local Settings\temp\

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Dec 25, 2008
  7. pisitcom

    pisitcom Private E-2

    :) Again,Thanks for your time.

    About thai date(Buddhist Era).I don't know how config effect this date system.I attempted to search from my attached files to get the data as you mentioned ie. "Utility Tray.lnk - c:\windows\system32\sistray.exe [2547-10-29 335872]" but failed.If you please tell me how to check. I may test another PC to see how this issues due to.

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://shell.windows.com/fileassoc/0...dir.asp?Ext=EX_
    I don't know this.

    I followed all of your guide(post#6) and get logs as attached.There was only one file couldn't delete as pic attached.

    :-D Now the infected PC come to work great. I can connect to internet and use this PC to answer this post.Thanks so much for all your help.
    Merry Christmas & A Happy New Year.
    Pisit
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what you are trying to say. You don't need to use search. You just need to make sure you have the clock on your PC set to the proper date and time. If you want it to display the Thai date then that's your decision, but you are going to have issues with some programs and malware scans if you do that. Some times files and folders set to future dates like this can cause them to be considered malware.

    The do the following to remove it.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://shell.windows.com/fileassoc/0409/xml/redir.asp?Ext=EX_

    After clicking Fix, exit HJT.


    Does this file still exist? Is it part of your ARDV whch may be getting picked up as malware by some tools?

    What about the below that ComboFix removed? Are they part of ARDV?
    g:\recycler\S-1-6-21-2434476501-1644491937-600003330-1213
    g:\recycler\S-1-6-21-2434476501-1644491937-600003330-1213\autorunme.exe
    g:\recycler\S-1-6-21-2434476501-1644491937-600003330-1213\Desktop.ini
     
    Last edited: Dec 28, 2008
  9. pisitcom

    pisitcom Private E-2

    Hello. So sorry for very lately reply.It was long weekend and after that it was very busy.

    About Thai date.This PC's user need like this.So I told them to beware as your advise.

    I have done the HJT as your advise.

    The file name"C:\WINDOWS\temp\FJ1726.EXE" was changed (by itself ) to "C:\WINDOWS\temp\DG3F26.EXE" but icon pic was same and I found it was Trend Micro file as attached Pic.Notice that Date Modified was exactly same. I can see DG3F26.EXE in Task Manager and if selected to End Process then "C:\WINDOWS\temp\DG3F26.EXE" was disappeared .

    The file that ComboFix removed from g:\recycler\. I'm not sure.It might be created by Ninja pendisk program(protect flash drive from malware)

    :-DAnd this PC still work great. I had installed Comodo,Spybot,Spyware Blaster as advise in "How to protect yourself from malware" since finished post #7.

    Thanks very much for all your help.
    Pisit
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Since the logs are all clean now, and if you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds