Page 2 of 3 FirstFirst 123 LastLast
Results 11 to 20 of 29

Thread: Another smitfruad-c problem with others

  1. #11
    Member
    Join Date
    Mar 2007
    Location
    Bangor, ME USA
    Posts
    29

    Post Logs

    Ok. AVG Shows Clean but i found a log from march that showed this and im wondering if it maybe hung around and didn't get clean all the way:

    Ok. AVG Shows Clean but i found a log from march that showed this and im wondering if it maybe hung around and didn't get clean all the way:

    -
    Mic

  2. #12
    Member
    Join Date
    Mar 2007
    Location
    Bangor, ME USA
    Posts
    29

    Default DOuble post

    somethings wrong with this.. ill try separate posts... heres HJT

    Logfile of HijackThis v1.99.1
    Scan saved at 20:22, on 2007-05-24
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.5730.0011)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Ahead\InCD\InCDsrv.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\pctspk.exe
    C:\WINDOWS\system32\svchost.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
    C:\Program Files\SpyCatcher 2006\Scheduler daemon.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\HJT\scanner.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: &Save Flash - {4064EA35-578D-4073-A834-C96D82CBCF40} - C:\Program Files\Save Flash\SaveFlash.dll
    O4 - HKLM\..\Run: [Resume copy] copyfstq.exe /startup
    O4 - HKLM\..\Run: [StartupDelayer] "C:\Program Files\r2 Studios\Startup Delayer\Startup Launcher.exe"
    O4 - HKLM\..\Run: [SpyCatcher Reminder] "C:\Program Files\SpyCatcher 2006\SpyCatcher.exe" reminder
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - Startup: Scheduler.lnk = C:\Program Files\SpyCatcher 2006\Scheduler daemon.exe
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
    O9 - Extra button: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7pro.dll
    O9 - Extra 'Tools' menuitem: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7pro.dll
    O9 - Extra button: iOpus iMacros - {0483894E-2422-45E0-8384-021AFF1AF3CD} - C:\Program Files\iMacros\imacros.dll
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
    O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
    O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O20 - AppInit_DLLs: interceptor.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
    O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe


    C:\WINDOWS\ODBCINST.INI : hii (64 bytes, MD5 D41D8CD98F00B204E9800998ECF8427E)
    Mic

  3. #13
    Member
    Join Date
    Mar 2007
    Location
    Bangor, ME USA
    Posts
    29

    Post logs

    here is the AVG report in question from March.

    Again, sorry for so many posts, the apple i'm working on hates me

    Mic
    Mic

  4. #14
    Member
    Join Date
    Mar 2007
    Location
    Bangor, ME USA
    Posts
    29

    Post Sorry!

    here tis. seems the copy/paste function on apple doesn't work so i may have to put it in manually or attach the log if you don't mind

    Again this is the one in question from march

    The infection found is called:

    [B]C
    Mic

  5. #15
    Member
    Join Date
    Mar 2007
    Location
    Bangor, ME USA
    Posts
    29

    Exclamation Hijacker.Costrat.l

    The infection is

    Hijacker.Costrat.l

    File where found is
    c:\Windows\lzx32.sys

    Also says file was cleaned but I wonder if remnants are still hanging around.
    Mic

  6. #16
    Member
    Join Date
    Mar 2007
    Location
    Bangor, ME USA
    Posts
    29

    Question SmitfraudFix log

    SmitFraudFix v2.186

    Scan done at 19:40:49.60, 2007-05-24
    Run from C:\Documents and Settings\BTN USER\Desktop\SmitfraudFix
    OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
    The filesystem type is NTFS
    Fix run in safe mode

    ªªªªªªªªªªªªªªªªªªªªªªªª SharedTaskScheduler Before SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "{5aaf6542-f4ba-4df4-873d-4902ecbe794c}"="acheweed"


    ªªªªªªªªªªªªªªªªªªªªªªªª Killing process


    ªªªªªªªªªªªªªªªªªªªªªªªª hosts



    ªªªªªªªªªªªªªªªªªªªªªªªª Generic Renos Fix

    GenericRenosFix by S!Ri


    ªªªªªªªªªªªªªªªªªªªªªªªª Deleting infected files


    ªªªªªªªªªªªªªªªªªªªªªªªª DNS



    ªªªªªªªªªªªªªªªªªªªªªªªª Deleting Temp Files


    ªªªªªªªªªªªªªªªªªªªªªªªª Winlogon.System
    !!!Attention, following keys are not inevitably infected!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "System"=""


    ªªªªªªªªªªªªªªªªªªªªªªªª Registry Cleaning

    Registry Cleaning done.

    ªªªªªªªªªªªªªªªªªªªªªªªª SharedTaskScheduler After SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll


    ªªªªªªªªªªªªªªªªªªªªªªªª End
    Mic

  7. #17
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,066

    Default

    hi micahr14,

    ok thanks for all the info.

    this:
    lzx32.sys is a rootkit that can arrive with smitfraud. thats from a avg scan from march? it will show in a smitfraud log and combofix log, but they dont remove it. you can do this to be sure:

    1. Download - rustbfix.exe ...and save it to your desktop:

    http://www.uploads.ejvindh.net/rustbfix.exe

    2. Double click on rustbfix.exe to run the tool.
    1. If a Rustock.b-infection is found, you will shortly hereafter be asked to reboot the computer. The reboot will probably take quite a while, and perhaps 2 reboots will be needed. But this will happen automatically.
    2. After the reboot 2 logfiles will open (%root%\avenger.txt & %root%\rustbfix\pelog.txt). If needed (still infected), post the content of these logfiles along with a new HijackThis log.

    shelf life
    How Can I Reduce My Risk?

  8. #18
    Member
    Join Date
    Mar 2007
    Location
    Bangor, ME USA
    Posts
    29

    Default logs

    Ok, there were no rootkits found. HJT log on the way as soon as I can get it. I've spent 3 straight days at work trying to fix our satellite feed from the syndicated network. We have an underground cable gone bad and digging it all up to get to that one area. May not post for a couple of days.
    Mic
    Mic

  9. #19
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,066

    Default

    hi micahr14,

    ok good no rootkits. just post back whenever you get a chance.

    shelf life
    How Can I Reduce My Risk?

  10. #20
    Member
    Join Date
    Mar 2007
    Location
    Bangor, ME USA
    Posts
    29

    Exclamation Issue

    ok we got another issue. when I right click on the taskbar and look at the toolbars they are all grayed out. The same is happening with the folder options. I've had this issue before. Also, ever since starting ZA Pro firewall up again it has stopped the internet connection between the file and the server (wherever it is). HJT revealed me nothing was infected ?? I've double checked the lines too. Somehow I think the virus has infected my explorer.exe file(s)

    Here is the Spybot log in the next post, it was the only thing I could get to work and pick up.
    Mic

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •