Virtumonde, Smitfraud-C Partially Removed

Discussion in 'Malware Help (A Specialist Will Reply)' started by Tom K, Dec 26, 2008.

  1. Tom K

    Tom K Private First Class

    Hello.
    I hope all of you at MajorGeeks enjoyed the holidays :)

    You have helped me greatly in the past. For nearly two years, I have had no significant malware or spyware issues! Unfortunately, I encountered an apparent Virtumonde and Smitfraud-C infection earlier tonight. It occurred while in the process of a single song download, however I am pretty sure the actual file I downloaded was not the problem, but rather the site itself which uses a format similar to YouTube and is a multimedia search site.

    I followed the instructions in the READ & RUN ME, and then followed the Windows XP Cleaning Procedure almost entirely. I'll briefly describe my results:

    SUPERAntiSpyware - Scanned full system, it found many infections, could not delete any, and got blue screen fatal stop error.

    SpyBot - Search & Destroy - Scanned full system, it found many Virtumonde and Smitfraud-C infections, apparently deleted them, but I do not think it was effective.

    Malwarebytes Anti-Malware - Quick system scan, found many Virtumonde and Smitfraud-C infections, deleted them. I think this is a very effective scanner.

    combofix.exe - I did not run this. I read the instructions at the link provided, but - to me - they were very complicated, and I felt very uncomfortable attempting this.

    MGtools.exe - Ran this tool, zip logs attached.

    It appears most of the infection has been removed, but I think some remnants remain. I am not getting the silent pop-ups that I was getting immediately after the infection, Windows now is shutting down normally without a message saying that explorer.exe is not responding, and the computer seems to be running normally now. However, the clock at the lower right-hand corner of the screen is awkward in that usually it displays the time as "3:50AM", but now it is displaying it as "03:50" So I suspect a problem still exists.

    Please review these logs and provide any assistance you can. Thank you very much.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The scans took care of most of it, however, part of your problem is that you are still running AVG7.5. This program is no longer supported, so I would suggest that you uninstall it and find another anti-virus program.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file and tell me how things are running.
     
  3. Tom K

    Tom K Private First Class

    Hey Tim,
    I ran into a few issues as I was attempting to perform the registry repairs, so I will wait for your reply before re-attempting to do so.

    First, I disabled all anti-virus and anti-spyware programs. I have several anti-spyware programs now installed, so I opened each one to see if it was running so I could temporarily disable it. When I went to open Malwarebytes Anti-Malware, a very strange small message window opened up that said that it could not configure i-tunes and was looking in the downloaded history files for a missing dll or something. I do not have this installed (and have no intention of ever doing so again), but did have quicktime a few years ago, and several months ago I thoroughly removed every trace of the i-tunes/quicktime tentacles that I could find. If there are any that remain, I want to eliminate them once and for all. Now when I open Malwarebytes Anti-Malware, it opens without incident and the message does not pop up.

    Second, I ran C:\MGtools\analyse.exe and did not find any of the three entries you said to fix. I did find some entries that I am concerned about and would appreciate if you could tell me if they are legit or not, and if they can be removed:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    I do not have any toolbars (Unless the Screenshot program is considered such, but I doubt it) installed on my browsers.

    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - h**p://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab
    I uninstalled all McAfee applications several months ago.

    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    I also want to add that halfway through the SpyBot - Search & Destroy scan performed earlier, as it was looking for Virtumonde infections, it stopped and a window came up that suggested stopping the scan and re-starting the computer. There were also two buttons, one to stop and one to continue, at the bottom of that window. As I saw no way to continue without using the buttons, I chose to continue, and the scan did so. Was this, most likely, prompted by the spyware to defend against its removal?

    I will wait for your reply before attempting any repairs. The computer continues to run normally, with the only exception I see being the clock formatted with a 24hr. reading over the usual AM/PM display. However, I want to eliminate all possible remnants of this problem. All anti-virus and anti-spyware programs are currenly re-enabled.

    Thank you again.
     
    Last edited: Dec 30, 2008
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please apply the reg. patch and then delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip. Go back to the Read and Run First instructions and re-download the latest version of MGTools.exe. Attach the new C:\MGLogs.zip.
     
  5. Tom K

    Tom K Private First Class

    Tim,

    Registry Patch has been applied. Clock remains in 24hr. mode with a single Windows tone sounding at Hr:00. New C:\MGLogs.zip log attached.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your clock should revert to normal mode when we do our final clean up and remove ComboFix. If it does not....just go to the control panel / regional and language / customize / time and set it for the format you want.

    Now, again you are running an outdated anti-virus and should uninstall it and choose another from HERE.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    And my last suggestion is that you download SP3.

    Tell me if the above reg patch was successful and any malware issues you may still have.
     
  7. Tom K

    Tom K Private First Class

    Hey Tim,

    Registry Patch has been applied. Clock remains in 24hr. mode with a single Windows tone sounding at Hr:00. Otherwise, the computer is running normally. No other unusual performance issues.

    Regarding the Anti-Virus protection, I am considering either AntiVir or AVG 8.0 Free. Do you know which one, or if both of them, offer automatic updates and real-time protection? I checked each programs description page, but they didn't completely answer the question.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Frankly I would go with either Antivir or Avast...avg 8 is a bit of a resource hog.

    Did you follow my instructions for resetting the clock?

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  9. Tom K

    Tom K Private First Class

    Tim,

    I uninstalled ComboFix, and restarted the computer. That did not restore the time display.

    I then followed your instructions for resetting the clock. Again, I restarted the computer. While it now appears normal, the Windows XP Critical Stop tone is still sounding on the top of the hour (ex.: 9:00 PM). This is not normal.

    I will wait for your reply before flushing and re-enabling System Restore.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Contol panel / sounds and audio devices / sounds / uncheck the box under program events.
     
  11. Tom K

    Tom K Private First Class

    I don't see any "box under program events", only one main box. I also don't want to disable ALL windows sounds, just the Windows XP Critical Stop tone sounding on the top of the hour.

    Another problem I just noticed now. When I check files and folders, it no longer displays the time in hh:mm:ss like it used to. It displays it as hh:mm.
    Essentially, I want the times on this computer to be as they were before the infection. Which is hh:mm tt on the taskbar and hh:mm:ss on files/folders. I screwed up trying to download that file from the site a week ago that started all this, but I want to get rid of the entire virtumonde/smitfraud-C infection.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then I would suggest that you post in the software section where others can assist you with those issues.....this is not malware related and unfortunately we are swamped with malware and need to address those issues. :(
     
  13. Tom K

    Tom K Private First Class

    Tim,

    Since my last post, I looked into the files and folders issue and have apparently fixed it.

    Before I post this issue in the Software section, there is one other thing I have to mention. Ever since this infection occurred, under "Windows Task Manager" in "running processes" there is an entry that has been in the top five, usually the first, called "rundll32.exe" in SYSTEM with a Mem Usage of 1208 K. Is this entry normal (not malware), and if it is, should it be the top process running?

    I understand the plethora of insidious malware issues you all deal with here everyday. Thanks again for your assistance.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rundll32.exe is a valid system file which executes a DLL. The actual command may be Rundll32.exe filename.xxx, <function>, whereas Task Manager reports only the command name and not it's parameter.

    You can check what it is referencing by:

     
  15. Tom K

    Tom K Private First Class

    Tim,

    I followed your instructions for identifying the Rundll32 modules. Interestingly, when I first attempted this no such process was identified and, sure enough, I checked running processes and it was not running. Shortly afterwards, I heard the Windows XP Critical Stop tone sounding on the top of the hour, I checked running processes again, and there it was. Apparently, Rundll32.exe is automatically starting. I re-attempted your instructions, and got the following log. I reviewed it, but I am really not sure if everything listed is legit. I have attached the Rundll32.txt log. Please review it and let me know if there is anything you see in it that is unusual.

    Thank you so much, again.
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    They are all legitimate items.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds