PDA

View Full Version : Smitfraud-C.CoreService



Ric34
2007-09-14, 22:04
OK i have seen this quite a few times but i cant find a thread. i need to know EXACTLY what it does and how to get rid of it... my computer has a LOT of viruses at the moment and this is the only one it cant seem to fix that hasnt made itself a part of spybot...

i saw that i needed to give you these, ill wrap code tags around it:



Error during check!: Innovagest2000.AlfaCleaner [27] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000004) ()


Error during check!: Innovagest2000.SpyDeface [11] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000014) ()


Error during check!: Innovagest2000.SpyDeface [12] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000014) ()


Error during check!: Innovagest2000.SpyDeface [13] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000014) ()


Error during check!: Innovagest2000.SpyDeface [24] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 0000000C) ()


Error during check!: Innovagest2000.SpyDeface [25] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000004) ()


Error during check!: Innovagest2000.XSRemover [6] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000014) ()


Error during check!: Innovagest2000.XSRemover [7] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000014) ()


Error during check!: Innovagest2000.XSRemover [8] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000014) ()


Error during check!: Innovagest2000.XSRemover [15] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 0000000C) ()


Error during check!: Innovagest2000.XSRemover [16] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000004) ()


Error during check!: Nous-Tech.UDefender [3] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000014) ()


Error during check!: Nous-Tech.UDefender [4] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000014) ()


Error during check!: Nous-Tech.UDefender [17] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 0000000C) ()


Error during check!: Nous-Tech.UDefender [18] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000004) ()


Error during check!: PestWiper [6] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000004) ()


Error during check!: Pimasoft.Spy Sniper [14] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 0000000C) ()


Error during check!: Rightclick.Pcast [38] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 0000000C) ()


Error during check!: ScanAndRepairUtilities2006 [7] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000004) ()


Smitfraud-C.CoreService: Data (File, fixing failed)
C:\WINDOWS\system32\drivers\core.cache.dsk

Smitfraud-C.CoreService: System file (File, fixing failed)
C:\WINDOWS\system32\drivers\core.sys

Error during check!: SpyQuake2 [41] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 0000000C) ()


Error during check!: SpyQuake2 [53] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 0000000C) ()


Error during check!: SpySheriff [11] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000004) ()


Error during check!: SpyCut [16] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000004) ()


Error during check!: SpyiBlock [2] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000014) ()


Error during check!: SpyShield [46] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 0000000C) ()


Error during check!: SpyShield [47] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000004) ()


Error during check!: SpyShield [48] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000014) ()


Error during check!: Spyware Disinfector [15] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000004) ()


Error during check!: SpywareQuake [33] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 0000000C) ()


Error during check!: SpywareQuake [34] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000004) ()


Error during check!: SpywareQuake [35] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000014) ()


Error during check!: SpywareStop [5] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000004) ()


Error during check!: SpywareXP [6] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000014) ()


Error during check!: SpywareXP [7] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000014) ()


Error during check!: SpywareXP [8] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000014) ()


Error during check!: SpywareXP [15] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000004) ()


Error during check!: SystemDoctor2006 [95] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 0000000C) ()


Error during check!: Virtual Bouncer [26] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000014) ()


Error during check!: WarezP2P [7] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 0000000C) ()


Error during check!: WarezP2P [10] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000004) ()


Error during check!: WarezP2P [86] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 0000000C) ()


Error during check!: Win32.Agent.hjo [7] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000004) ()


Error during check!: Win32.ZenoSearch [4] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000014) ()


Error during check!: Winsoftware.WinAntiVirusPro2007 [29] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 0000000C) ()


Error during check!: WorldAntiSpy [13] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 0000000C) ()


Error during check!: WorldAntiSpy [14] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000004) ()


Error during check!: WorldAntiSpy [57] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 0000000C) ()


Error during check!: WorldAntiSpy [58] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000004) ()


Error during check!: Zlob.HQvideo [11] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000014) ()


Error during check!: Zlob.XpassGenerator [2] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000014) ()


Error during check!: Zlob.XpassGenerator [3] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000014) ()


Error during check!: Zlob.XpassGenerator [6] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000004) ()


Error during check!: 3wPlayer [1] (Access violation at address 005A4BA7 in module 'SpybotSD.exe'. Read of address 00000004) ()


Smitfraud-C.MSVPS: Text file (File, fixed)
C:\WINDOWS\dat.txt

Zlob.DNSChanger: Settings (Registry value, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\kdid


--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---

2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2005-11-06 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2007-05-23 advcheck.dll (1.5.3.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2007-07-31 Tools.dll (2.1.2.0)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2007-09-12 Includes\Cookies.sbi (*)
2007-07-25 Includes\Dialer.sbi (*)
2007-09-12 Includes\DialerC.sbi (*)
2007-08-29 Includes\Hijackers.sbi (*)
2007-09-12 Includes\HijackersC.sbi (*)
2007-07-25 Includes\Keyloggers.sbi (*)
2007-09-12 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2007-09-12 Includes\Malware.sbi (*)
2007-09-12 Includes\MalwareC.sbi (*)
2007-09-05 Includes\PUPS.sbi (*)
2007-09-12 Includes\PUPSC.sbi (*)
2007-09-12 Includes\Revision.sbi (*)
2007-05-30 Includes\Security.sbi (*)
2007-09-12 Includes\SecurityC.sbi (*)
2007-09-12 Includes\Spybots.sbi (*)
2007-09-12 Includes\SpybotsC.sbi (*)
2007-08-21 Includes\Tracks.uti
2007-09-12 Includes\Trojans.sbi (*)
2007-09-12 Includes\TrojansC.sbi (*)
2007-06-06 Plugins\TCPIPAddress.dll


if someone could help me i would VERY much appreciate it, and thanks in advance...

EDIT: there was a LOT more to the code thing, but i had to delete it from 174040 characters to 20000... if you need more to help, just ask and i'll send it to you...

tashi
2007-09-18, 08:59
Hello.


my computer has a LOT of viruses at the moment

If you can find the file/s, please zip and send to: detections(AT)spybot.info (Replace AT with @)
If you cannot, please don't concern yourself.

Spybot-S&D version 1.5 has been released.

Spybot - Search & Destroy Version 1.5 Download (http://www.spybot.info/en/download/index.html)



Uninstall previous version (http://www.safer-networking.org/en/howto/uninstall.html)



Tutorial (http://www.spybot.info/en/tutorial/index.html)


After installation make sure you update to the latest definitions, then run another scan.
When the scan completes, right click on the results list, select "Copy results to clipboard".
Copy paste (Ctrl+V) those results to a new post in this thread.

Regards. :)

Ric34
2007-09-19, 20:53
The forum will not let me post up the results as they are too large... WAY too large... what can i do???

tashi
2007-09-19, 21:17
Hi there.

Sounds like you captured the full report which you can send to: detections(AT)spybot.info (Replace AT with @)

Please follow the procedure in this link:
"BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

Start your own thread in the Malware Removal Forum (http://forums.spybot.info/forumdisplay.php?f=22) so we can take a different look at the system via a HJT log.

Cheers.