Welcome to Help4Web.co.uk - Web Design Help, Html Tutorial, Php, Asp , SQL help and CCNA, MCSE definitions!
Google
Webkpop-web.com

     Main Menu

· Home
· Free Downloads
· Computing FAQ
· Contact Us
· Free Software Downloads
· Tech Forum
· Technology News
· Web Design Help
· Web Links
· Your Online Account
· Your PM



     Web Browser


     Website Links
Supermediastore! #1 in Computer media & Accessory

White Papers IT
Learn Korean
Chinese Pop Music
Advertise Kpop
Korean Pop Site Map
Web Design
Pop Music
Chinese Girls
HK Pop Korean Music
Lee Hyori
Hyori
Boa Park Ji Yoon
Baby Vox YG Family
Jeon Ji Hyun
1 Tym Ha Ji Won
Shyne Rain Bi
Shin Mina SM Town
Fly to the Sky
Korean Girls and Models
Nicholas Tse
161 Clan
보아
Edison Chen
Sung Hi Lee
Shinhwa
Andy Lau Jay Chou
White Papers
Case Study SES
Kelly Chen
Liu Yi Fei Sammi Cheng
Jordan Chan Music
Computer Jobs IT

Computer Help Forum and Programming Advice :: View topic - Got hit with Smitfraud C.
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Log inLog in 

Got hit with Smitfraud C.

 
Post new topic   Reply to topic    Computer Help Forum and Programming Advice Forum Index -> Information Security
View previous topic :: View next topic  
Author Message
Jon
Web Design Admin
Web Design Admin


Joined: Jul 12, 2004
Posts: 72

PostPosted: Tue Dec 13, 2005 12:21 am    Post subject: Got hit with Smitfraud C. Reply with quote

1) I got hit with Smitfraud C.. Upon opening IE, it would instantly switch to one of two web site that were desperately trying to get me to sign up for a variety of anti-virus software: Winantivirus, Ad-Protect, Spy Fighter, on a web page titled "Security Troubleshooting", and Spy Trooper, Spy Axe, Spy Guard, on a web page titled "Online Security Center." The next day a "Spy Axe" icon showed up on my desk top, along with one in the Launch Window.

2) Every few minutes there is a window popping up by the system tray stating that computer is infected with "iworm_attck_vi22.02a"

3) From time to time various ads are poping up, example:casino, etc.

4) From time to time other notices pop up, for example "you computer is running slow, is infected, etc.

5) Also, Norton is reporting that the computer is getting hit with "Hacktook. Rootkit", and Norton is denying access, but is stating thai it is not able to repair it.

6) Norton is also defeating a Trojan called "Spaxe"

7) I was able to defeat the Browser take over by disabling a BHO, titled "hp6D32l.tmp" using "BHO Demon". This allows my normal access to the internet via Yahoo.

Cool Computer is a Pentium 4, with XP.

9) Ran Ad-Ware Personal SE, Norton Premier, and SpyBot. SpyBot found Smitfraud, but was not able to fix one of two files. It fixed a registry value.....policies\explorer\run\nvctrl.exe, but was not able to fix a registry-change value.....Internet setting\Zone Map\Domains\Windows\free-spy-cam.net\*!=W=4>

10) These problems came very suddenly, when I opened a news article in Yahoo. The broswer shut down instantly, and two icons showed up on my desk top representing the two files stated above. I haven't had any virus problems for three years, and bingo, it happens. The take over was not the "blue death" I have read about.

11) Norton is running, SpyBot, and Ad-Ware and Microsoft ad-ware are not running. Microsoft firewall is on.

12) Below is a HijackThis log taken in the "non-safe" mode. I would appreciate a bit of help on this one. Is their any programs out there that will remove this beast, or must it be removed manually, and how difficult is it to do?

13) I disabled "System Restore" and ran Norton again thinking that I would find something hidden in there but nothing showed.


Logfile of HijackThis v1.99.1
Scan saved at 12:17:51 AM, on 12/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\mssearchnet.exe
C:\WINDOWS\system32\nvctrl.exe
C:\WINDOWS\SYSTEM32\USRmlnkA.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\SYSTEM32\USRshutA.exe
C:\WINDOWS\SYSTEM32\USRmlnkA.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\hijackthis2\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com
O2 - BHO: (no name) - {1ca480cd-c0e5-4548-874e-b85b17905b3a} - C:\WINDOWS\system32\hpC672.tmp
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program

Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [USRpdA] C:\WINDOWS\SYSTEM32\USRmlnkA.exe RunServices \Device\3cpipe-USRpdA
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Norton Ghost 9.0] C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: BHODemon 2.0.lnk.disabled
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -

http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) -

https://www-secure.symantec.com/tech...a/SymAData.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) -

https://www-secure.symantec.com/tech...ActiveData.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -

http://download.mcafee.com/molbin/is...45/mcfscan.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec

Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec

Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec

Shared\ccSetMgr.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton

SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton

Ghost\Agent\PQV2iSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton

SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation -

C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation -

C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common

Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec

Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec

Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security

Center\SymWSC.exe
_________________
Free MusicCpopServer Definition
Back to top
View user's profile Send private message Visit poster's website
ci5co
Web Design Newbie
Web Design Newbie


Joined: Aug 18, 2004
Posts: 89

PostPosted: Tue Dec 13, 2005 12:22 am    Post subject: Reply with quote

Please do the following.


1- Download smitRem
and save the file to your desktop.
Right click on the file and extract it to it's own folder on the desktop.

2- Download the trial version of Ewido Security Suite from HERE.
Install it (When installing, under "Additional Options" uncheck : -Install background guard and -Install scan via context menu), and update the definitions to the newest files. Do NOT run a scan yet.

---------------------------------------------------------------------

Reboot your computer in Safe Mode (at startup tap F8 and select Safe Mode) .

1- Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.
Wait for the tool to complete and disk cleanup to finish.

The tool will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.

2- Run Ewido:
Click on scanner
Click Complete System Scan and the scan will begin.
During the scan it will prompt you to clean files, click OK
When it asks if you want to clean the first file, put a check in the lower left corner of the box that says "Perform action on all infections" then choose clean and click OK.
When the scan is finished, click the Save report button at the bottom of the screen.
Save the report to your desktop
Close Ewido

------------------------------------------------------------------------

Reboot in normal mode and here:
- Post a new HijackThis log.
- Copy/paste the Ewido report, please.
_________________
White Papers

Internet Marketing

Boku
Back to top
View user's profile Send private message Visit poster's website
Display posts from previous:   
Post new topic   Reply to topic    Computer Help Forum and Programming Advice Forum Index -> Information Security All times are GMT + 10 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum







Learn Chinese | Learn cantonese | Learn Mandarin | Grace Park | Party Organisers | Kaila yu | Phone Card | Twins | Chinese Society | Loans UK | BokuMaro | CV Help Book | Chinese Wife | Korean Singles | British Born Chinese | Bae Yong Jun | Speak Korean | Chinese Models | Music | Information Security Management | Maritime Greenwich Campus | Covering Letters Help | Chinese Music | Jang Nara | SES | YG Family | Learn Korean | Firewall Definition | Server Definition | Wireless Network Definition | E-Commerce Definition | Sales Leads | Application Firewall | CCNA definitions | Research Papers | Webcast | CV Help

Author KPop Music :- Jon Bock ( Chinese Pop Music Learn Korean )
Produced by Kpop-Web Design Associates, all rights not reserved.
Internet Marketing and Search Engine Optimisation Software Defined Radio