Unsolved

This post is more than 5 years old

9 Posts

21430

March 26th, 2008 20:00

identify source of virus

Hello,

 

Today I used the Dell On Call service to diagnose and resolve what I believed to be a virus.  I'm upset b/c I made it clear several times to the dell rep that my main goal was to identify the source of the viruses.  I asked her if she could do that and several times she said yes.  She ran two scans (smetfraud and smetrem) and removed the viruses.  She told me that since she had removed them, there was no way to identify their origin.  Is this true?  Is there any way to find my computer's infection history and identify a likely source, such as a website where the download occurred?   

2.9K Posts

March 26th, 2008 21:00

I don't know of any malware that leaves an "installed by ,,,,,," traceable signature. It will be interesting to hear if anyone else has had experience with this.

2 Intern

 • 

2.2K Posts

March 26th, 2008 22:00

Being indentifiable and traceable would defeat the whole purpose of spyware.:smileywink:

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

March 26th, 2008 22:00

another example of "professional" DELL "help" messing-around where [i believe] they shouldn't:

 

First, there was no reason for them to have you run BOTH Smitfraud(fix) AND SmitRem.

 

SmitRem, by NoahdFear, is no longer maintained --- it has not been updated in almost TWO (2) years.  

 

This is due to the overwhelming popularity and success of SmitFraudFix, by S!ri, which has essentially rendered SmitRem obsolete.

 

Both programs come with disclaimers from their authors, that they should only be used under proper (i.e., EXPERT) supervision --- ideally in conjunction with HiJackThis analysis --- lest these powerful tools yield pejorative consequences:   to cite one common example, both SmitRem and SmitFraudFix will reset the user's background/WallPaper.   This will happen even if SmitRem or SmitFraudFix try to repair a "clean" system (i.e., one not infected with a SmitFraud variant).   As such, the general public should take great care against indiscriminately running these tools on their own!

 

Second, and even more significantly, unless you gave the DELL person more information than simply saying you had a "virus", I have to wonder why they even decided to attempt a repair using SmitFraudFix/Smitrem:   These two tools specifically fix so-called "SmitFraud variants" --- typically a  "Rogue program" --- that was installed via a "Zlob trojan".  

These are malware programs, not viruses!!  

So I repeat my question, why did the person even suggest their use in the first place, if they were going after a "virus"???

 

SmitFraud/Zlob trojans are one of the two most common class of malware currently in circulation... (the other one being vundo/virtumonde)... and sad to say, the potential sources for each is virtually unlimited :smileymad:

Message Edited by ky331 on 03-26-2008 07:45 PM

9 Posts

March 26th, 2008 23:00

Oh no!  Buyer's remorse!  They charged me $239!  I had a bad feeling about doing it, b/c I've had great success in the past using HiJackThis on my own through this very forum.  The main reason I considered using the Dell On Call service, as I explained numerous times to the rep on the phone, was for the outside chance there was a way to find the source of the virus.  He assured me she would be able to do that, and then completely reneged later on.  It was some dude in India, no doubt, so I wonder if he really understood what I was asking him, or whether he was just making empty promises to get me to agree to the service charge, in other words: a bait and switch.

 

So this leads me to my next question for anyone who might know.  I'm basically trying to determine who, out of two users, is responsible for infecting the computer.  Although the system was equipped with McAfee Antivirus software, both users visited sights that were risky in terms of malware.  One mainly used LimeWire, the other mainly used online gaming sights and downloaded video games.  The LimeWire guy (my son) was gone for several months, and gave the video game guy permission to use his computer, on the condition that nothing be downloaded.  Of course, video game guy did not respect Limewire guy's wishes and went ahead and downloaded video games and played them online.  During the several months that Limewire guy was gone, and while video game guy was using the computer, the monitor went black and the computer was basically kaput and just wouldn't respond or do anything.  (He then had the brilliant idea to "fix" the problem by wiping the hard drive and erasing all of Limewire's files- but that's a whole separate issue).  Does this give a clue as to when the virus was likely downloaded?  The Indian dude from Dell told me that a virus will start causing noticable problems with a computer very soon after it is downloaded, so whoever was the user of the computer at the time it crashed is the culprit.  I'd like to get second opinions from other people regarding this issue.         

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

March 26th, 2008 23:00

this may not answer your question, but I'd like to make a few points:

 

first, unless you consider a person to be completely trustworthy, you simply can't allow ANYONE to "use" (or "share" ) your PC... even for just "a minute".   That's all it takes to allow the infection to enter and spread.

i realize it can be awkward... particularly if it's a family member... to tell them to "keep off".   But allowing someone access to your PC is analogous to allowing someone unrestricted entry into your house/bedroom... knowing that the cash and jewelry are sitting out in plain site!!!

 

second, you continue to talk of viruses.... indicating that you have McAfee.  

Anti-virus is only one degree of protection nowadays... it's essential... but not sufficient by itself.

You also need a firewall, ONE "resident" anti-spyware program, several on-demand anti-spyware scanners, and ideally, some "passive"/preventive protection as well.   

 

all those will help.... but ultimately, it's "the driver behind the wheel", who, despite seat-belts and anti-lock brakes... causes the crash.

Message Edited by ky331 on 03-26-2008 09:05 PM

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

March 27th, 2008 01:00

while it is likely that a virus... or a Smitfraud-variant / Zlob Trojan... will be immediately noticeable to the user, it doesn't always have to be the case:   there have been some instances when a virus (or other malicious program) was downloaded, but with a "delayed triggering mechanism" --- typically, it was programmed to wait until a particular date on the calendar (e.g., "the Ides of March" ), at which point it would first "take over" your machine and begin to inflict its damage.
Message Edited by ky331 on 03-26-2008 10:33 PM

9 Posts

March 27th, 2008 01:00

Points well taken, definitely, regarding shared usage.  Thanks for the tip of creating the separate restricted-use account. 

 

One thing I neglected to make clear in my quesetion: the computer actually belongs to Limewire guy- he's the one who shared his computer with video game guy. 

 

So does anyone know whether what the Dell support person told me is in fact true?  That a virus will inflict noticable damage to a computer very soon after being downloaded?  It's true that both guys were irresponsible users, but I'd like to try to determine which one likely downloaded the virus that was fatal to the computer.  If Limey was out of town for months, and gameboy was the only one using it during the period of time that it crashed, is it safe to assume gameboy unwittingly downloaded the virus that caused the crash?

March 27th, 2008 01:00

That particular piece of garbage can hit from several different areas. It can come as a "drive by" download (you won't even know that it happened until it's too late) from an infected site. P2P programs are notorious for adding little "gifts" to the files being downloaded. Videogame guy very possibly was prompted to download a necessary codec -- which in fact, is completely bogus -- that contained the Trojan.

In addition to the suggestions made by ky331, and if you plan on letting other people use your computer, you should create a separate "Guest" account with limited accessibility. That way the guest user cannot download anything. You can password protect your account (DON'T give anyone else the password) and anyone else must use the Guest account.

You could also tell LimeWire guy and Videogame guy that when they can spring for their own computer, they can put anything that they want to on it, but YOUR computer is off limits. (Easier said than done, I know LOL) Unfortunately, at my house, LimeWire guy and Videogame guy were one in the same. Good luck :) -- SCB

4 Apprentice

 • 

20.5K Posts

March 27th, 2008 03:00

amoney758,

Please post the following logs:
1. C:\smitfiles.txt.
2. C:\rapport.txt

Thank you.

9 Posts

March 27th, 2008 23:00

Hi!  Thanks so much for offering to help.  Smitfiles:

 

smitRem © log file
     version 3.2

     by noahdfear


Microsoft Windows XP [Version 5.1.2600]
"IE"="6.0000"
The current date is: Wed 03/26/2008
The current time is: 17:30:11.48

Running from
C:\Documents and Settings\Avery's computer\Desktop\smitRem

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Pre-run SharedTask Export

(GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
Copyright(C) 2006 BleepingComputer.com

Registry Pseudo-Format Mode (Not a valid reg file):

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Appinitdll check ........ Thank you Grinler!

dumphive.exe (C)2000-2004 Markus Stephany
REGEDIT4

[Windows]
"AppInit_DLLs"=""
"DeviceNotSelectedTimeout"="15"
"GDIProcessHandleQuota"=dword:00002710
"Spooler"="yes"
"swapdisk"=""
"TransmissionRetryTimeout"="90"
"USERProcessHandleQuota"=dword:00002710

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

XP Firewall allowed access

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


 checking for ShudderLTD key

ShudderLTD key not present!

 checking for PSGuard.com key


PSGuard.com key not present!


 checking for WinHound.com key


WinHound.com key not present!


 checking for drsmartload2 key


drsmartload2 key not present!

spyaxe uninstaller NOT present
Winhound uninstaller NOT present
SpywareStrike uninstaller NOT present
AlfaCleaner uninstaller NOT present
SpyFalcon uninstaller NOT present
SpywareQuake uninstaller NOT present
SpywareSheriff uninstaller NOT present
Trust Cleaner uninstaller NOT present
SpyHeal uninstaller NOT present
VirusBurst uninstaller NOT present
BraveSentry uninstaller NOT present
AntiVermins uninstaller NOT present
VirusBursters uninstaller NOT present

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 Existing Pre-run Files


 ~~~ Program Files ~~~

 

 ~~~ Shortcuts ~~~

 

 ~~~ Favorites ~~~

 

 ~~~ system32 folder ~~~

amcompat.tlb
nscompat.tlb


 ~~~ Icons in System32 ~~~

 

 ~~~ Windows directory ~~~

 

 ~~~ Drive root ~~~


 ~~~ Miscellaneous Files/folders ~~~

 


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 2524 'explorer.exe'
Killing PID 2524 'explorer.exe'
Killing PID 2524 'explorer.exe'
Killing PID 2524 'explorer.exe'
Killing PID 2524 'explorer.exe'
Killing PID 2524 'explorer.exe'
Killing PID 2524 'explorer.exe'

Starting registry repairs

Registry repairs complete

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

SharedTask Export after registry fix

(GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
Copyright(C) 2006 BleepingComputer.com

Registry Pseudo-Format Mode (Not a valid reg file):

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Deleting files

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 Remaining Post-run Files


 ~~~ Program Files ~~~

 

 ~~~ Shortcuts ~~~

 

 ~~~ Favorites ~~~

 

 ~~~ system32 folder ~~~

 

 ~~~ Icons in System32 ~~~

 

 ~~~ Windows directory ~~~

 

 ~~~ Drive root ~~~


 ~~~ Miscellaneous Files/folders ~~~

 

 ~~~ Wininet.dll ~~~

 CLEAN! :)

 

 

 

 

Here is the rapport.txt file:

 

 

SmitFraudFix v2.308

Scan done at 17:27:23.60, Wed 03/26/2008
Run from C:\Documents and Settings\Avery's computer\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts


127.0.0.1       localhost

»»»»»»»»»»»»»»»»»»»»»»»» VACFix

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

S!Ri's WS2Fix: LSP not Found.


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


»»»»»»»»»»»»»»»»»»»»»»»» IEDFix

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: 3Com 3C900TPO-based Ethernet Adapter (Generic) - Packet Scheduler Miniport
DNS Server Search Order: 192.168.1.1

HKLM\SYSTEM\CCS\Services\Tcpip\..\{D1975F17-E786-409F-A288-3A0D51588EE4}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{D1975F17-E786-409F-A288-3A0D51588EE4}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{D1975F17-E786-409F-A288-3A0D51588EE4}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
 
Registry Cleaning done.
 
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End

 

 

 

 

Thanks so much again.

4 Apprentice

 • 

20.5K Posts

March 28th, 2008 01:00

Thanks for posting those. The source of the infection does not show in those logs.
How is the computer running now? Are your malware symptoms gone?
Don't forget to delete the logs and the tools if they were left on your computer.

9 Posts

March 28th, 2008 20:00

Hi Bugbatter,

 

Thanks again for your time.  The computer seems to be OK, but one thing hasn't changed.  After video game guy wiped the hard drive clean (in his brilliant attempt to "fix" the virus problem), there has been a sort of high-pitched whirring noise whenever the computer is turned on.  I'm not sure what this noise is, or how to get rid of it.  Any ideas on what it might be?

 

Also, I'm thinking maybe I should go through the steps for HiJackThis, just to be on the safe side?  What do you think? 

March 28th, 2008 20:00

Hi amoney758,

......there has been a sort of high-pitched whirring noise whenever......

That sounds more like something mechanical such as the power supply fan or the fan that cools the processor. Most of us don't stop to think that dust can build up inside the computer case and so never think about opening it and cleaning the dust out. Places like RadioShack sell small cans of compressed air that can be used to clean the dust out of those fans. Alternately, a soft brush such as a makeup brush (get a new one, don't use one that has been used to apply makeup) can be used to gently brush the dust out.

As Bugbatter said, the logs that you provided showed no signs of (that) infection so your HijackThis probably wouldn't either. However, just to make sure that neither LimeWire guy or video game guy didn't download any other little "presents" posting a log might be a good idea. :)
-- SCB

4 Apprentice

 • 

20.5K Posts

March 28th, 2008 21:00

"video game guy wiped the hard drive clean (in his brilliant attempt to "fix" the virus problem)"
How did he "wipe" the HD? You were still infected after that?

9 Posts

March 29th, 2008 15:00

Thanks for that suggestion.  Where do I go to find the log files?
No Events found!

Top