Computing.Net > Forums > Security and Virus > Suspect a Trojan

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Suspect a Trojan

Reply to Message Icon

Name: Brett J
Date: November 17, 2003 at 17:08:54 Pacific
OS: W2K Pro SP4
CPU/Ram: Celeron 500 / 192 RAM
Comment:

Aternoon all,
Long time lurky/admirer, first time poster. I am having fits trying to isolate anything about this infection. Being brand new to W2K isn't a huge help I must admit.

Symptoms:
Password window bypassed at logon, Admin Tools/services being reset, browser constantly reverting to unknown alternate, Shmgrate.exe placed Set Program Access and Defaults in Add/Remove Programs window, unable to 'fix' (03) Toolbar or (04) [ICQ Lite] with HT, windows search works intermittently, cannot access 'Internet' under IE/tools/options...highly suspect of registry manipulation. Local settings missing from both named user and Administrator, cannot access clipbook and/or files ....

Cleaning and removal:
Spybot S&D, Adaware, TrendMicro, SwatIt and PC Flank all show nothing found (all with latest engines, pattern file, signatures, etc.) (absolutely no inication anywhere here)

This is a "bare bones" net machine however it is used every day and it is flat out frustarting as I am pretty hands on and have never had a bug sitch I could not find an answer to until now... Posting HT log and also SwatIt as it is slightly different(shows additional start items and a ZA anomoly)
Thanks to anyone who can help.
Brett


Logfile of HijackThis v1.97.6
Scan saved at 4:28:09 PM, on 11/17/2003
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\ZONELABS\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\locator.exe
C:\WINNT\Explorer.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Swat It Professional\SwatItPro.exe
C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Yahoo!\Messenger\YPager.exe
C:\Documents and Settings\brett\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [SwatItPro] C:\Program Files\Swat It Professional\SwatItPro.exe /tray
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O17 -HKLM\System\CCS\Services\Tcpip\..\{223C6CC4-443D-42DE-8E14-05ECA62216F2}: NameServer = 204.118.6.2

SwatIt:mobsync.exe, Registry Run (Synchronization Manager),

mobsync.exe /logon, C:\WINNT\system32\
hpztsb04.exe, Registry Run (HPDJ Taskbar Utility),

C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb04.exe,

C:\WINNT\system32\spool\drivers\w32x86\3\
SwatItPro.exe, Registry Run (SwatItPro), C:\Program

Files\Swat It Professional\SwatItPro.exe /tray,

C:\Program Files\Swat It Professional\
ICQLite.exe, Registry RunOnce (ICQ Lite), C:\Program

Files\ICQLite\ICQLite.exe -trayboot, C:\Program

Files\ICQLite\
ZoneAlarm.lnk, Shell Startup Folder, C:\Documents and

Settings\All Users\Start

Menu\Programs\Startup\ZoneAlarm.lnk, C:\Documents and

Settings\All Users\Start Menu\Programs\Startup\
ZoneAlarm.lnk, User Shell Startup Folder,

%ALLUSERSPROFILE%\Start

Menu\Programs\Startup\ZoneAlarm.lnk,

%ALLUSERSPROFILE%\Start Menu\Programs\Startup\

shmgrate.exe, Active Setup

(>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}),

"C:\WINNT\System32\shmgrate.exe" OCInstallUserConfigOE,

C:\WINNT\System32\
end ::



Sponsored Link
Ads by Google

Response Number 1
Name: Imp
Date: November 17, 2003 at 17:49:13 Pacific
Reply:

Hello Brett,
I think the best would be you use that excellent program called "Trojan Remover"
This is a freeware for one month, then a shareware for the modic amount of 25$ to get unlimited updates
This program is the best compromise for people not so familiar with the trojan's betrayal, it works alone, the free download give you a complete updated program to try.
Trojan Remover at:
http://www.simplysup.com/tremover/details.html


0

Response Number 2
Name: Brett J
Date: November 17, 2003 at 18:53:03 Pacific
Reply:

Imp,
Thanks for the input.

I loaded and tried Trojan Remover with no luck. As with the others TR detected nothing. As an aside to the original post, I have further discovered that the Send To folder displays quite an assortment of files that appearently have been collected and redirected.. This is going to be a quite cute, I suspect.. I'll keep digging and you keep smiling
Regards
Brett


0

Response Number 3
Name: Hammermill
Date: November 18, 2003 at 18:37:31 Pacific
Reply:

Go here for an on-line trojan scan:

http://www.trojanscan.com/trojanscan/trojanscan.htm


0

Response Number 4
Name: Irrepressable
Date: November 19, 2003 at 13:43:54 Pacific
Reply:

We are going through something VERY SIMILIAR to what you are here!

We've been taken, but cannot find any trojan either. I think it is because they may have gotten rid of their entryway themselves...

We have 3 pcs here, and many, MANY odd things are going on. There are files we did not put on the systems, things making duplicates without us doing it, and lots of software that I didn't load! I discovered that my own pc has been made into a SERVER, and I seem to be hosting a gaming site!

If I delete unknown files, they reappear right before my eyes! I don't know much about networking, but I do know that I am now a "web server" or something, and that my pc is sending out broadcasting messages. (Right now I'm borrowing a laptop from the ex-husband to research this).

I changed some of the security settings, and disallowed anyone connecting to my "domain" from deleting their cache - now I have lots of visited web pages that I did not visit! Philidelphia newspapers, and some written in Greek (real Greek!).

Looking for a trojan won't be the answer, finding out how to REMOVE A DOMAIN and/or WinSock Server, possibly a MIRRORED drive, will be.

And if you do, please help me!
Deb


0

Response Number 5
Name: Brett J
Date: November 20, 2003 at 07:40:41 Pacific
Reply:

Deb,
Sounds like we have the same issues and possibly the same Trojan..

I allowed Services and controller brief access to as a server last evening and found it listening on port 1025.. One of the NetSpy ports.. So, could be NetSpy buried deep in memory. 1025 is also tagged as a source of enrty fo a couple games...
Whatever this is has created a user shell, It's own desktop, copied Zone Alarm and reconfigured it and added an instance of IE4 as it's personal browser. It/They moved text, email, image, fax folders to the desktop (My Documents) and hijack Clipboard to copy to. I am denied access to new users Administrative Tools and to the reconfigured ZA. Clues I have are the registry Run key shows Mobsync.exe /logon which sets the stage at bootup and a radio toolobar that doesn't show anywhere in startup picked up by HT.. (the above are just the high points many other issues)I'm with you, I need help, only spinning my wheels now... Have tried every trojan scan I can find plus Adaware and Spybot S&D CW Shredder Anyone with any ideas ?

Best luck, Deb I'll keep you advised on this thread...you do the same
Brett


0

Related Posts

See More



Response Number 6
Name: Brett J
Date: November 20, 2003 at 07:46:53 Pacific
Reply:

Deb
I forgot to add that this is almost assured to be a trojan and unless and until it is removed from memory any changes we make are likely to be reversed and it will just keep re-occuring
Brett


0

Response Number 7
Name: John C. Hillyer II
Date: December 6, 2003 at 23:04:24 Pacific
Reply:

"Who is on first?"
First one running, or first to modify the system is Commander.

Once a system is well-compromised, no inspection of that system from within that system will reveal, even in time domain. Fortunately, most spyware is junk and visible from within the affected system.

Externally monitoring, we'll see lost time from expert 'bots' managing system use, but nothing is reported from within. The best recourse is a fresh install of the operating system from trusted ROM, e.g, a retail CD-ROM.

For MS Windows, before accessing the network for updates/patches, disable excess local services (e.g. www publishing svc), and connect only through a firewall.

This principle applies to secure communications. When a stealthy monitor is installed at either communcation endpoint where the communications are deciphered, one need not crack monster-key communications, just let the host system do it and read the result.


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Suspect a Trojan

SPOOLSV.EXE a trojan? www.computing.net/answers/security/spoolsvexe-a-trojan/7894.html

how to get rid of a trojan www.computing.net/answers/security/how-to-get-rid-of-a-trojan/16502.html

Panda found a trojan...can't find folder www.computing.net/answers/security/panda-found-a-trojancant-find-folder/976.html