Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Smitfraud-c. infected rundll32.exe file [Solved]


  • This topic is locked This topic is locked

#1
EldonM

EldonM

    Member

  • Member
  • PipPip
  • 32 posts
Ok before posting this I have already run at least 5 different anti-virus', many many spyware/adware scan, registry checkers, the whole nine yards. I have looked through the forums several times and tried to use the advice already given, but to no avail.

I'm very computer literate, but even this has got me in a bind.
Recently my mmorpg account was compromised which of course prompted me to clean virus' and such. Since then I have not once typed in my password. Good ole' copy and paste. that was a month ago now I have been receiving emails that a password reset has been requested(not by me) prompting me yet again check my computer. Vundo(Virtumonde) virus was found and has been successfully removed. Four Days Later again a request for a password reset. Now I am thinking WTH. Again scanned my computer and lo and behold smitfraud-c. has been found. I also noticed in my task manager that 2 rundll32.exe file has been running and wasn't there before. I have tried everything to remove it. When I change the name of the file and then delete I no longing have access to my display properties or my security center. I had to find a replacement rundll32.exe file to fix the problem. When I run Spybot S&D and still finds it as a smitfraud-c. I've looked up this virus and the strange thing is that is doesn't affect my system like the description says, to my knowledge, only that I still feel that this virus is being used to steal my private information(from the continued password requests). Here is my hijack this file. Notice the 2 rundll32.exe files running. Those weren't there before. Those Files are what Spybot is identifying as smitfraud-c.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:18:49, on 12/23/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

--
End of file - 1456 bytes


I run a very clean system(as you can see from the very short hijack list lol) and only use it for gaming and some internet. I use Spybot S&D, MBAM, RegCure, and CCleaner for PC Health and I run then almost daily now because of this. Please Help Me :)

New Symptom!! 12-23-08
It seems when I kill the runddl32.exe files after a certain amount of time the critical error sound goes off(just the sound and I think it's that critical error sound) and the rundll32.exe files are back running. It happens maybe like 1-2 hours after killing the process.

Also should I have that many svchost.exe files running? In my task manager I have 7 different svchost.exe files running on startup.

Update!!
Ran another smitfraudfix in safemode, another anti-virus, and another cleaner with no change. here is a screenshot of Spybot still recognizing the virus.
Untitled.png

Edited by EldonM, 23 December 2008 - 12:09 PM.

  • 0

Advertisements


#2
OldTimer

OldTimer

    Global Moderator

  • Global Moderator
  • 3,273 posts
Hello EldonM and welcome to G2G. No, you cannot delete the rundll32.exe file. It is a system files and is required by the operating syste. In and of itself, it doesn't do anything but load dll files for use. If it was loading a bad dll, that is the file that we would want to see. As for the password reset, there might or might not be anything physically present on this system. On most sites, only an account name is required to ask for a reset so if someone else already has the account name, they can make that request at any time. Most sites will send an email to the registered user's email account warning of the request and instructions on how to complete it.

Before running a new scan let's clean out the temporoary folders.

Download ATF Cleaner to your Desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Click Select All found at the bottom of the list.
  • Click the Empty Selected button.
If you use Firefox browser, do this also:
  • Click Firefox at the top and choose Select All from the list.
  • Click the Empty Selected button.
  • NOTE : If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser, do this also:
  • Click Opera at the top and choose Select All from the list.
  • Close ALL Internet browsers (very important).
  • Click the Empty Selected button.
  • NOTE : If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

Now download OTScanIt2.exe to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt2 on your desktop.

Note: You must be logged on to the system with an account that has Administrator privileges to run this program.
  • Close ALL OTHER PROGRAMS.
  • Open the OTScanIt2 folder and double-click on OTScanIt2.exe to start the program (if you are running on Vista then right-click the program and choose Run as Administrator).
  • Click the Scan All Users checkbox on the toolbar.
  • Do not change any other settings.
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
  • Close Notepad (saving the change if necessry).
Use the Add Reply button and Attach the scan back here (do not copy/paste it as it will be too big to fit into the post). It will be located in the OTScanIt2 folder and named OTScanIt.txt.

I will review it when it comes in.

Cheers.

OT
  • 0

#3
EldonM

EldonM

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts
Everytime i Run the OTScan it locks up and is non responsive
  • 0

#4
OldTimer

OldTimer

    Global Moderator

  • Global Moderator
  • 3,273 posts
Hi EldonM. What does it say in the statusbar? You can't always go by that because some systems simply can't keep up with updating it and stop performing the statusbar update. Look at the hard drive light also and see if it is still flickering. If so, then it's doing its thing. Let it run. Remember to close all other applications and don't do anything on the system while it is running.

Cheers.

OT
  • 0

#5
EldonM

EldonM

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts
kk I've ran that OTScan backwards sideways through the rear and around again ive run it is everymode ive let it run for 5 yes 5 straight hours and itll just run for like a whole 5 seconds and freeze. Now after tryng to run that scan my internet now suddenly shuts off consistently and mozilla opens incredibly slowly. is this something the scan caused? I spent at least 4 hours just so my computer could recieve internet from my wireless router.

Oh to answer your questions the status bar freezes on what evdr program is freezes on it is never the same. No the drive light no longer "flickers". The program just becomes unresponsive. ive even run it by not clicking scan all users and it still freezes up. here a nice picture.


so far this is going from bad to worse!! whats going on T.T

well imma try a few thing please get back to me

Attached Thumbnails

  • NotResponding.jpg

Edited by EldonM, 27 December 2008 - 10:18 PM.

  • 0

#6
EldonM

EldonM

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts
oh since this came up as different from my last hijacklist i figure ill post it

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:19:14 PM, on 12/27/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe

--
End of file - 2182 bytes
  • 0

#7
OldTimer

OldTimer

    Global Moderator

  • Global Moderator
  • 3,273 posts
Hi EldonM. There's so little running on that system I don't know. Looking at that my guess would be a corrupted driver. Try running it in Safe Mode. If that doesn't work then select None for the Drivers section and see what happens. If that works then most likely there is a corrupted driver entry in the registry.

Cheers.

OT
  • 0

#8
EldonM

EldonM

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts
And god said let there be light..!!

Lo and behold I selected None for the drivers and it ran smoothly and fully in seconds.

Which I think is good and bad news T.T

here is the log.

So if it is a corrupted driver, whats the next step?

Attached Files


  • 0

#9
EldonM

EldonM

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts
Ok never mind that last post T.T

I just ran it one more time With the normal settings again and it ran all the way through just as good T.T

heres the list

I think I'm about to huck the thing out my window :)

Attached Files


Edited by EldonM, 28 December 2008 - 02:12 PM.

  • 0

#10
OldTimer

OldTimer

    Global Moderator

  • Global Moderator
  • 3,273 posts
Hi EldonM. Yeah, computers, they do strange things lol.

There nothing showing anywhere in the log. Everything is as it should be. My guess is that whatever was finding something was finding it in the browser cache or possibly the restore points. We'll clean both of those out.

I would also recommend getting an anti-virus application installed on this system. With no protection at all, something could easily get downloaded from a website or from and email. And there would be absolutely nothing to stop it. While AVs cannot stop everything out there today, they can stop many things and it would be prudent to at least have a first line of protection in place to address these threats.

First, let's clean out the temp folders and browser caches:

Start OTScanIt2. Copy/Paste the information in the codebox below into the pane where it says "Paste fix here" and then click the Run Fix button.

[Empty Temp Folders]

The fix should only take a very short time. When the fix is completed a message box will popup either telling you that it is finished, or that a reboot is needed to complete the fix. If the fix is complete, click the Ok button and Notepad will open with a log of actions taken during the fix.

If a reboot is required, click the "Yes" button to reboot the machine. After the reboot, OTScanIt2 will finish moving any files that could not be moved during the fix and NotePad will open with the final results at that time.

Close Notepad and OTScanIt2.

Next, let's reset the System Restore points and remove all of the tools we used during the fix and then you are all set.

Step #1

Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected)1. Turn off System Restore.On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.
2. Restart your computer.

3. Turn ON System Restore.On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check Turn off System Restore.
Click Apply, and then click OK.
[/list]System Restore will now be active again.

Step #2

To remove all of the tools we used and the files and folders they created do the following:
  • Start OTScanIt2
    Click the CleanUp button
  • OTScanIt2 will delete any tools downloaded and files/folders created and then ask you to reboot so it can remove itself. Click Yes.
After that you are good to go.

Cheers and Happy Computing!

OT
  • 0

#11
EldonM

EldonM

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts
My Response to this situation, opinion, and advice.

Though you guys did offer some help I think I found most of the problems on my own, but yet this was a first time experience for me so I have nothing to base anything on, so good work and Thank you for the help.

If you have constant problem with a rundll32.exe file continouslyt turning itself on...Check your scheduled task folder. So obvious yet so overlooked. I know I did.

Never go blindly removing things with anti-viruses and fixes. I honestly think I cause more trouble for myself thne this mystery virus did.
  • 0

#12
OldTimer

OldTimer

    Global Moderator

  • Global Moderator
  • 3,273 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP