PDA

View Full Version : Smithfaudc & Virtumonde



Feaker
2008-01-15, 16:12
***LOG IS LONGER THAN POST****

Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 10/01/2008
Kaspersky Anti-Virus database records: 506695
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
Z:\

Scan Statistics:
Total number of scanned objects: 80972
Number of viruses found: 30
Number of infected objects: 250
Number of suspicious objects: 2
Duration of the scan process: 00:57:49

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3ad391678a806ec4d691e83aaa393b6f_50e417e0-e461-474b-96e2-077b80325612 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WebBuyingAssistant.zip/v1.8.6/wbuninst.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WebBuyingAssistant.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\COMPS10\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-53b20017-2208ae95.zip/Counter.class Infected: Trojan.Java.ClassLoader.i skipped
C:\Documents and Settings\COMPS10\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-53b20017-2208ae95.zip/VerifierBug.class Infected: Trojan.Java.ClassLoader.k skipped
C:\Documents and Settings\COMPS10\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-53b20017-2208ae95.zip/Beyond.class Infected: Trojan.Java.ClassLoader.k skipped
C:\Documents and Settings\COMPS10\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-53b20017-2208ae95.zip ZIP: infected - 3 skipped
C:\Documents and Settings\COMPS10\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-53b20018-405179ea.zip/Counter.class Infected: Trojan.Java.ClassLoader.i skipped
C:\Documents and Settings\COMPS10\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-53b20018-405179ea.zip/VerifierBug.class Infected: Trojan.Java.ClassLoader.k skipped
C:\Documents and Settings\COMPS10\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-53b20018-405179ea.zip/Beyond.class Infected: Trojan.Java.ClassLoader.k skipped
C:\Documents and Settings\COMPS10\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-53b20018-405179ea.zip ZIP: infected - 3 skipped
C:\Documents and Settings\COMPS10\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cnte-dhncgts.jar-3335a716-7dc4d427.zip/BnnnnBaa.class Infected: Trojan.Java.ClassLoader.as skipped
C:\Documents and Settings\COMPS10\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cnte-dhncgts.jar-3335a716-7dc4d427.zip/VaannnaaBaa.class Infected: Trojan.Java.ClassLoader.as skipped
C:\Documents and Settings\COMPS10\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cnte-dhncgts.jar-3335a716-7dc4d427.zip/Bnnnnn.class Infected: Trojan.Java.ClassLoader.as skipped
C:\Documents and Settings\COMPS10\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cnte-dhncgts.jar-3335a716-7dc4d427.zip ZIP: infected - 3 skipped
C:\Documents and Settings\COMPS10\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-54e1bfcf-2e170008.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\COMPS10\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-54e1bfcf-2e170008.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\COMPS10\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-54e1bfcf-2e170008.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
C:\Documents and Settings\COMPS10\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-54e1bfcf-2e170008.zip ZIP: infected - 3 skipped
C:\Documents and Settings\COMPS10\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ms0311.jar-5e909fe3-6571d7a1.zip/TakePrivileges.class Infected: Trojan.Java.ClassLoader.an skipped
C:\Documents and Settings\COMPS10\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ms0311.jar-5e909fe3-6571d7a1.zip/Installer.class Infected: Trojan-Downloader.Java.Agent.a skipped
C:\Documents and Settings\COMPS10\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ms0311.jar-5e909fe3-6571d7a1.zip ZIP: infected - 2 skipped
C:\Documents and Settings\COMPS10\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\COMPS10\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\COMPS10\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\COMPS10\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\COMPS10\Local Settings\Application Data\Musicmatch\Jukebox\mmjbaltlog.txt Object is locked skipped
C:\Documents and Settings\COMPS10\Local Settings\Application Data\Musicmatch\Jukebox\mmjblog.txt Object is locked skipped
C:\Documents and Settings\COMPS10\Local Settings\Application Data\Musicmatch\MIM\Database\Default.ldb Object is locked skipped
C:\Documents and Settings\COMPS10\Local Settings\Application Data\Musicmatch\MIM\Database\Default.mdb Object is locked skipped
C:\Documents and Settings\COMPS10\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\COMPS10\Local Settings\History\History.IE5\MSHist012008011020080111\index.dat Object is locked skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\JETFE66.tmp Object is locked skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\RCX26.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\RCX3B.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\RCX3E.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\RCX40.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\RCX41.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\RCX43.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\RCX46.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\RCX47.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\RCX4D.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\RCX50.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\RCX53.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\RCX57.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\RCX5A.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\RCX6A.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\RCX6D.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\RCX70.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\RCX76.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\RCX7F.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\RCX82.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\RCX86.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\RCX89.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\RCX8F.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\RCX98.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\RCX9B.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\REDE1723.ac$ Object is locked skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\sdexe.exe Infected: Trojan-Downloader.Win32.PurityScan.ez skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\snapsnet.exe/data0006 Infected: Trojan-Downloader.Win32.VB.ccs skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\snapsnet.exe NSIS: infected - 1 skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\UND70B91.ac$ Object is locked skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\yazzsnet.exe/data0003 Infected: Trojan-Downloader.Win32.PurityScan.fg skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\yazzsnet.exe NSIS: infected - 1 skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\~DFEB79.tmp Object is locked skipped
C:\Documents and Settings\COMPS10\Local Settings\Temp\~DFEBAE.tmp Object is locked skipped
C:\Documents and Settings\COMPS10\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\COMPS10\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\COMPS10\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe Infected: Trojan-Dropper.Win32.Agent.dgo

Feaker
2008-01-15, 16:13
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:56:59 AM, on 1/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\dla\tfswctrl .exe
C:\Program Files\Analog Devices\Core\smax4pnp .exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched .exe
C:\WINDOWS\system32\hkcmd .exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\WINDOWS\system32\igfxpers .exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
F3 - REG:win.ini: load=C:\WINDOWS\system32\pmkhf.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm .exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA3897] command /c del "C:\WINDOWS\system32\drivers\core.cache.dsk_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5564] cmd /c del "C:\WINDOWS\system32\drivers\core.cache.dsk_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingA631] command /c del "C:\WINDOWS\system32\pmkhf.dll_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8472] cmd /c del "C:\WINDOWS\system32\pmkhf.dll_tobedeleted"
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [WebBuying] C:\Program Files\Web Buying\v1.8.6\webbuying.exe
O4 - HKCU\..\Run: [Dot1XCfg] C:\Program Files\Dot1XCfg\Dot1XCfg.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{78E2962B-B7D4-4DF0-B4DA-06E9A97C1871}: NameServer = 151.164.11.201,151.164.1.8
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\..\{78E2962B-B7D4-4DF0-B4DA-06E9A97C1871}: NameServer = 151.164.11.201,151.164.1.8
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\Internet Explorer\dicorunuj.html

--