Smitfraud and Others I think, please help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by brianz37, May 27, 2008.

  1. brianz37

    brianz37 Private E-2

    Had the smitfraud wallpaper, was infected with this once before, ran smitfraudfix and was ok. This time it does not work. Keep getting popups from task bar, and can not down load anything as IE is being redirected. Loaded superantispyware from flash drive. Had spybot search and destroy on computer, ran this also. I am unable to do alot because I can't download anything, it seems when I donwnload on another computer and move with a flash drive, I can't get program to run on laptop. Also keep getting Data Exectution Prevention shutting down windows explorer and notepad. Below is the hijack this log copied from my laptop, I hope this is right, as notepad keeps shutting down. Any help would be great.

    Thanks in advance!
     
    Last edited by a moderator: May 27, 2008
  2. abri

    abri MajorGeek

    Hi brianz37,
    Welcome to Major Geeks!


    If you still have the HJT log and can attach it, that would be helpful. Also, see if you can get us a copy of the scan from USING MG TOOLS. This scan doesn't attempt any changes to your computer so it might be possible to get it to run. Try it in normal mode if possible, in safe mode if normal mode isn't possible. Let me know how this goes.

    abri
     
  3. brianz37

    brianz37 Private E-2

    Thanks for the help abri. I work 12 hr night shifts, so sometimes it will take awhile between replys.
    I have attached the files that you requested, not sure which of the MGtools logs that you need. If you need more, I will get what you need.

    Thanks again.
    Brian
     

    Attached Files:

  4. brianz37

    brianz37 Private E-2

    Here are the rest of the MG logs.

    Brian
     

    Attached Files:

  5. abri

    abri MajorGeek

    Hi brianz37,

    You have a lot of malware. I hope the following set of instructions will allow you to go back to the READ & RUN ME FIRST when you're finished, as we can't see all the files without the rest of the logs.

    Please begin by doing the below instructions. If something doesn't work, make a note of it and tell us what happened, then just continue on. Your computer is not in normal startup mode with msconfig. How to set this correctly is described in the instructions.



    1) Please look at the contents of this folder and remove anything that Windows will allow you to remove and that is not something you need to keep:


    C:\Documents and Settings\All Users\Application Data\TEMP



    2) If you do not use Windows Messenger (not to be confused with MSN Messenger!!) I would like you to run Disable/Remove Windows Messenger


    3a) Go to start> control panel> administrative tools> services> scroll down to " Windows Action Scriptl" and double click it. In the window that opens look for startup type, use the arrow on the right to get the selections and select disable. Click apply> ok. Exit administrative tools.

    3b) Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (Note: if using Vista, don't double click, use right click and select Run As Administrator). Select Do a system scan only). In the box that opens, find the following entries and put a checkmark next to them (if you need some of them to be in the trusted zone, leave them). After check-marking them, close all your open browser windows and click on FIX:


    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\xwusuhzh.exe,
    O2 - BHO: (no name) - {bc97b254-b2b9-4d40-971d-78e0978f5f26} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O20 - Winlogon Notify: ddcDvVlL - ddcDvVlL.dll (file missing)
    O23 - Service: Windows Action Script - Unknown owner - C:\WINDOWS\system32\scvhost.exe (file missing)

    After you click fix, just close hijackthis.



    4) Go to add/remove programs and uninstall the below:

    J2SE Runtime Environment 5.0 Update 11"
    J2SE Runtime Environment 5.0 Update 6"
    J2SE Runtime Environment 5.0 Update 9"
    J2SE Runtime Environment 5.0"
    Java(TM) 6 Update 3"
    Java(TM) SE Runtime Environment 6 Update 1



    5) Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the 'Execute' button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt



    6) Now run CCleaner at the default setting with the Windows tab as the top one.



    7) Install the current version of Sun Java from: Sun Java Runtime Environment


    8) Before you go back to begin the instructions in the READ & RUN ME FIRST, first please run C:\MGtools\GetLogs.bat and attach the fresh MGlogs.zip. You do not have to find and post these files individually as you did the first time. They will be located as a zip file called MGlogs.zip and you can find them directly under C:\ with the files (not folders). When you come here to post and click on the Manage Attachments buttons, look for them in that location.


    I also want you to attach the Avenger log.


    Please note when you start the instructions in the READ & RUN ME, that your computer is not in normal startup mode. You need to change this. There are instructions in the READ ME with regard to msconfig. Please take note of those.


    Let me know how things are running now? (I will not be here for several days. Either someone else will help you or I'll get back to you as soon as I'm back. Thanks for your patience.

    abri
     
    Last edited: May 29, 2008
  6. brianz37

    brianz37 Private E-2

    Thanks abri,

    I made it through to step #7, my internet is still being redirected. Anything that I type into the address bar or any link that I click is redirected. My favorites seem to be fine, they go were they are supposed to. Also, note pad is still being shut down, (Data Execution Prevention message). I used microsoft word to copy the text that you wanted me to copy. I have attached the logs that you wanted. Some of the files did not show up when I ran C:\MGtools\analyse.exe

    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\xwusuhzh.exe,
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O23 - Service: Windows Action Script - Unknown owner - C:\WINDOWS\system32\scvhost.exe (file missing)

    I had already removed all of the java files after I posted the first set of logs, and I belive I used the norton logs for the xwusuhzh.exe to repair that.

    The laptop seems to be running a bit faster now, as when opening files and windows. I'll go back and start with the READ & RUN ME FIRST now.

    As a note, I know where I was infected, it was at:

    www.cmt.com/shows/series/can_you_duet/series.jhtml

    It looked as though norton tried to do something, I got alot of messages from norton and a bunch of pop-ups, the computer froze for a couple of minutes while the site loaded and that was that, and here I am.

    Thanks again for your help!
    Brian
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please refer to step 1 of the READ & RUN ME and use MSconfig to put your PC into normal startup mode as requested you must remain in normal startup mode. The please try to complete the instructions in the READ & RUN ME now and get all the logs attached. You have signs of a rootkit we need to remove and we are going to need a log from ComboFix to continue with this.
     
  8. brianz37

    brianz37 Private E-2

    Hello,

    Thanks again for the help, I have run everything in read and run me. It seems that every thing is pretty much back to normal. Machine taking quite awhile to boot. Running in normal startup mode. All logs are attached.

    Thanks,
    Brian
     

    Attached Files:

  9. brianz37

    brianz37 Private E-2

    MG logs attached.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have Spybot's Teatimer running! You must disable this now as requested in the READ ME. See this link: How to disable Spybot's TeaTimer

    After you disable Teatimer, continue with the below.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups. Make sure that you use REMOVE!

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  11. brianz37

    brianz37 Private E-2

    OK, made it through all that you requested.
    Did not find the following line:
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    I did receive a success message about adding text to the registery.
    How long does it normally take for combo fix to reboot? Machine was at "Windows is shutting down" for 45min. and then I powered off. Combofix continued at power up.
    Computer seems to be running pretty smoth. Still slow on boot, get just a black screen for up to a couple of minutes before windows splash screen.
    I have attached the requested logs.

    Thanks again,
    Brian
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Something on your PC is preventing it from running properly. If you look at the log you just posted you will see the below:
    This probably cause it to never finish running.

    Computer seems to be running pretty smoth. Still slow on boot, get just a black screen for up to a couple of minutes before windows splash screen.


    [/quote]This is most likely due to the programs you are running at startup, like
    • NeroFilterCheck
    • Adobe Reader Speed Launcher
    • Adobe Photo Downloader
    • GoogleToolbarNotifier
    • MSN Messenger
    • Symantec
    • GoogleUpdater,
    • Intel\Wireless which includes the below 3 services
      • EvtEng
      • OwnershipProtocol
      • RegSrvc
    • InCD Helper
    • NVIDIA Display Driver Service
    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    10. Go to add/remove programs and uninstall HijackThis.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     
  13. brianz37

    brianz37 Private E-2

    Thank you for your help. It has been much appreciated. Running much better now.

    Brian
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds