Smitfroud + more problems!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by peter_g8, Nov 15, 2006.

  1. peter_g8

    peter_g8 Private E-2

    Hello there

    I have had a recent attack of the spyware, within the last week it has been multiplying like rabbits on my computer. Unable to clean it using spybot and adaware alone, I ran your entire process on malware removal, all the scans etc. The only difference I did was adding in the removal of smitfroud as well (during an extra reboot into safe mode). I thought I had fixed it.

    What has all this achieved? Nothing by the looks. All the same crap has returned with a vengance (including smitfroud). I have (or will) attach all the log files as requested in the site guide including:
    # BitDefender
    # PandaActiveScan.
    # GetRunKey
    # ShowNew
    # HijackThis - Mid scans while attempting to remove smitfroud
    # HijackThis - After all scans

    Also, a new virus has popped up that norton (corporate edition) is unable to clean:
    Scan type: Realtime Protection Scan
    Event: Virus Found!
    Virus name: Trojan.Busky
    File: C:\WINDOWS\system32\merpxkk.dll
    Location: C:\WINDOWS\system32
    Computer: MOONDOG
    User: SYSTEM
    Action taken: Clean failed : Delete failed : Access denied
    Date found: Wed Nov 15 13:01:52 2006

    Hoping someone can help :)

    Cheers

    Pete
     

    Attached Files:

  2. peter_g8

    peter_g8 Private E-2

    more log files
     

    Attached Files:

  3. peter_g8

    peter_g8 Private E-2

    And the smitfroud removal tool log as well...
     

    Attached Files:

  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download Pocket KillBox
    • Save it to your desktop or a place easy to find.
    • Do not run it yet
    Please look in Add/Remove Programs for the following and uninstall them if found:

    DeluxeCommunications

    After uninstalling the above, see this thread on Using SDFix. After you complete this scan, attach the log to your next post with a fresh HJT log. Also I would like a fresh Panda log.

    Please see the below thread on how to install and run VundoFix.Once you complete the scan above, attach the log from the scan, along with the SDFix log, HJT log and fresh Panda log.
     
  5. peter_g8

    peter_g8 Private E-2

    Thanks for that. I had actually found another fix for vundo, but I ran everything you said anyway. The computer seems better now, though adware still lurks down the back. See the logs anyway.

    Cheers mate, its a relief to have this crap off my system.

    Pete
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Before we begin let's make a small dent, see this thread on Using SDFix.

    Once you complete the above, reboot and attach the results along with a fresh HJT log.
     
  7. peter_g8

    peter_g8 Private E-2

    Apologies, I did run SDFix before, just forgot to attach the log.

    Ran it again, and hijackthis, logs attached.

    Pete
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    While BJ is not around, I'll try to help keep you moving along. You have a lot of malware problems and we need to work this in stages. Let's continue with the below which will help remove some of your problems.
    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!
     
  9. peter_g8

    peter_g8 Private E-2

    Well, I tried running combofix. It ran, says it found "SurfSideKick", then it says it needs to exit and will restart, but nothing happens. The log file doesnt say anything, but here are all the logs anyway.

    Cheers

    Pete
     

    Attached Files:

  10. peter_g8

    peter_g8 Private E-2

    And one more log

    Oh, and the computer is working OK, no major problems. Aside from the odd warning that my computer is infected and I need to install their dodgy program. And an annoying continuous alert in the taskbar. I went through the forum topic on preventing spyware, did everything, and am now running zone alarm firewall now, instead of comodo (seemingly crap).

    Thanks for everything :)
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you still have a bunch to fix!

    Goto Add/Remove Programs and uninstall the below malware are requested in step 0 of the READ ME.
    MediaTickets by OIN

    Continue by downloading a tools we will need - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    O2 - BHO: (no name) - {2F5E4CF7-7AE0-BFBA-8E46-0112CCE18336} - (no file)
    O2 - BHO: (no name) - {51DB88C5-4EC9-4D4E-A63A-1580B08F12EF} - C:\WINDOWS\system32\jkkll.dll (file missing)
    O2 - BHO: (no name) - {84363A45-FD80-E40D-8FAF-D82894043ACF} - C:\WINDOWS\system32\odhgb.dll
    O2 - BHO: (no name) - {D89423EB-BC27-A4AC-2905-C2896E2B669D} - C:\WINDOWS\system32\vuzc.dll
    O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
    O4 - HKLM\..\Run: [merpxkk.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\merpxkk.dll,qdxbrgf
    O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvlus.dll,startup

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Documents and Settings\Peter\Application Data\Dxcknwrd.dll
    C:\Documents and Settings\Peter\Application Data\Security Alert
    C:\DXC9.exe
    C:\misb.exe"
    C:\windows_e53.exe
    C:\WINDOWS\system32\wnsintcc.exe
    C:\WINDOWS\system32\ddcaxut.dll
    C:\WINDOWS\system32\drvlus.dll
    C:\WINDOWS\system32\drvnex.dll
    C:\WINDOWS\system32\drvzus.dll
    C:\WINDOWS\system32\merpxkk.dll
    C:\WINDOWS\System32\mtwirl.dll
    C:\WINDOWS\system32\odhgb.dll
    C:\WINDOWS\system32\vuzc.dll
    C:\WINDOWS\system32\ybeeg.tmp
    C:\WINDOWS\system32\llkkj.ini
    C:\WINDOWS\system32\ybeeg.ini
    C:\WINDOWS\system32\ybeeg.ini2
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete if found:
    C:\Program Files\DeluxeCommunications

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT

    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  12. peter_g8

    peter_g8 Private E-2

    OK, did everything you requested, and it all went nice and soothly. The only discrepancy was that this item wasnt in the HJT:

    O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvlus.dll,startup

    Everything seems fine though. The logs are attached.

    Im very happy to have a (seemingly) spyware free computer :D

    Cheers mate

    Pete
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean! Let's get to the final steps but first you should update Sun Java (it changed to update 10 & you have 9 ) and consider using the 2.0 version of FireFox.


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 9
    Mozilla Firefox (1.5.0.8)

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds