Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

troyan-spy.html.smitfraud.c


  • Please log in to reply

#1
marko2005

marko2005

    New Member

  • Member
  • Pip
  • 2 posts
ok, so

yesterday i got infected with some spyware, my desktop was blue and black with a spyware infection message, and i saw that someone had similar problems, so i followed the instructions give in that topic. it didnt quite work, so i asked around a little more, got a few tools (ewido, smitrem...), and also found out that it was the smitfraud trojan.
i think that i managed to remove most of it, my desktop is almost back to normal, and i dont get any more infection messages, but i still have a few problems.
my computer is VERY slow now, sometimes windows wont even start, my browser is hijacked no matter what i try, and a number of things dont work as they used to...

i used addaware, spybot, ewido, and a few other programs, but nothing seems to help

can someone please help me with this problem, i would be very thankful
  • 0

Advertisements


#2
marko2005

marko2005

    New Member

  • Topic Starter
  • Member
  • Pip
  • 2 posts
this is my hijack this log






Logfile of HijackThis v1.99.1
Scan saved at 11:51:01, on 25.11.2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\csrss.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
G:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
G:\WINDOWS\system32\spoolsv.exe
d:\marko\BlueSoleil\BTNtService.exe
d:\marko\security suite\ewidoctrl.exe
d:\marko\Eset\nod32krn.exe
G:\WINDOWS\System32\nvsvc32.exe
G:\Program Files\T-Com MAXadsl CD-ROM\T-Com Siemens ADSL A-100 Modem\Adsl\dslstat.exe
G:\Program Files\T-Com MAXadsl CD-ROM\T-Com Siemens ADSL A-100 Modem\Adsl\dslagent.exe
G:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
G:\Program Files\QuickTime\qttask.exe
D:\marko\BlueSoleil\BlueSoleil.exe
G:\WINDOWS\System32\wuauclt.exe
G:\WINDOWS\msstream.exe
G:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\marko\Winamp\winamp.exe
D:\marko\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = /4.3.10
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = /4.3.10
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = /4.3.10
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = /4.3.10
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = /4.3.10
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = /4.3.10
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,First Home Page = /4.3.10
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = /4.3.10
O4 - HKLM\..\Run: [DSLSTATEXE] G:\Program Files\T-Com MAXadsl CD-ROM\T-Com Siemens ADSL A-100 Modem\Adsl\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] G:\Program Files\T-Com MAXadsl CD-ROM\T-Com Siemens ADSL A-100 Modem\Adsl\dslagent.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] G:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "G:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - Global Startup: BlueSoleil.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = G:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &ICQ Toolbar Search - res://D:\marko\ICQToolbar\toolbaru.dll/SEARCH.HTML
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - d:\marko\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - d:\marko\ICQLite\ICQLite.exe
O20 - Winlogon Notify: avpe32 - G:\WINDOWS\SYSTEM32\avpe32.dll
O23 - Service: BlueSoleil Hid Service - Unknown owner - d:\marko\BlueSoleil\BTNtService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - G:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - G:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - G:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - d:\marko\security suite\ewidoctrl.exe
O23 - Service: MSCSPTISRV - Sony Corporation - G:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - d:\marko\Eset\nod32krn.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - G:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - G:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - G:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP