Scan your PC for Errors

Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] smss.exe getting hijacked!

[Fixed] Hijackthis! Logs - [Fixed] smss.exe getting hijacked! posted in the Security & Safety forums; How/where is the smitrem log? The prevx files don't seem to like being uploaded.. but here's a brief excerpt from the full-on prevx log I found [08/05/2006 21:14:48][ WKCOM] - ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #15  
Old 05-09-2006
Bronze Member
 
Join Date: Mar 2006
Posts: 17
iMagnusX - See this Members User comments on their Profile page
Default

How/where is the smitrem log? The prevx files don't seem to like being uploaded.. but here's a brief excerpt from the full-on prevx log I found

[08/05/2006 21:14:48][ WKCOM] - >>> QUERY: Type(NXD) Pid(200014000) QueryId(335) ActionToTake(BLOCKED) Actor(WINLOGON.EXE)
[08/05/2006 21:14:48][ WKCOM] - QueryResponse( QueryId=335, policyId=200014000, Allow=0)
[08/05/2006 21:14:48][ PAWS] - PAWS alert queued
[08/05/2006 21:14:48][ WKCOM] - >>>>>>>>>>>>> Multiple events detected.
[08/05/2006 21:14:48][ WKCOM] - >>> EVENT: Type(NXD) Pid(200014000) QueryId(335) ActionTaken(DENIED) Actor(WINLOGON.EXE)
[08/05/2006 21:14:48][ WKCOM] - >>> EVENT: Type(NXD) Pid(200009000) QueryId(335) ActionTaken(DENIED) Actor(WINLOGON.EXE)
[08/05/2006 21:14:48][ WKCOM] - >>>>>>>>>>>>> Multiple events detected.
[08/05/2006 21:14:48][ PAWS] - PAWS alert queued
[08/05/2006 21:14:48][ PAWS] - PAWS alert queued
[08/05/2006 21:14:48][ WKCOM] - >>> EVENT: Type(NO) Pid(320001000) QueryId(0) ActionTaken(ALLOWED) Actor(WINLOGON.EXE)
[08/05/2006 21:14:48][ WKCOM] - >>> EVENT: Type(NO) Pid(320001000) QueryId(0) ActionTaken(ALLOWED) Actor(WINLOGON.EXE)
[08/05/2006 21:14:48][ WKCOM] - >>> QUERY: Type(NXD) Pid(200014000) QueryId(336) ActionToTake(BLOCKED) Actor(WINLOGON.EXE)
[08/05/2006 21:14:48][ WKCOM] - QueryResponse( QueryId=336, policyId=200014000, Allow=0)
[08/05/2006 21:14:48][ PAWS] - PAWS alert queued
[08/05/2006 21:14:48][ WKCOM] - >>> EVENT: Type(NO) Pid(320001000) QueryId(0) ActionTaken(ALLOWED) Actor(WINLOGON.EXE)
[08/05/2006 21:14:48][ PAWS] - PAWS alert queued
[08/05/2006 21:14:48][ WKCOM] - >>>>>>>>>>>>> Multiple events detected.
[08/05/2006 21:14:48][ WKCOM] - >>> EVENT: Type(PT) Pid(220000000) QueryId(0) ActionTaken(ALLOWED) Actor(STUB_EXE_WIN32GUI.BIN)
[08/05/2006 21:14:48][ PAWS] - PAWS alert queued
[08/05/2006 21:14:48][ WKCOM] - >>>>>>>>>>>>> Multiple events detected.
[08/05/2006 21:14:48][ WKCOM] - >>> EVENT: Type(NXD) Pid(200014000) QueryId(336) ActionTaken(DENIED) Actor(WINLOGON.EXE)
[08/05/2006 21:14:48][ WKCOM] - >>> QUERY: Type(NXD) Pid(200014000) QueryId(337) ActionToTake(BLOCKED) Actor(WINLOGON.EXE)
[08/05/2006 21:14:48][ WKCOM] - QueryResponse( QueryId=337, policyId=200014000, Allow=0)


  #16  
Old 05-10-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

That is not like what you posted in youre first post , does that activity also still continues?

The tool will create a log named smitfiles.txt on the drive that you ran Smitrem on, eg; "C:\smitfiles.txt" , or the partition where your operating system is installed on.
So in youre case that would be I:\smitfiles.txt it seems.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #17  
Old 05-10-2006
Bronze Member
 
Join Date: Mar 2006
Posts: 17
iMagnusX - See this Members User comments on their Profile page
Default

Yeah, I know. What I posted previously is the Prevx pop-up window alerting me that it has blocked something from working. The log I found seems to be the action-to-action log that Prevx makes, located in the Program Files folder. Here's the smitrem log, thanks for reminding me where it was.

And yes, the activity continues, although the prevx "px-log" is a 1.5 megabyte file, but here's another sampling from the past few minutes:

[09/05/2006 22:03:38][ PAWS] - queueing paws alert...
[09/05/2006 22:03:38][ PAWS] - PAWS alert skipped
[09/05/2006 22:03:38][ PAWS] - queueing paws alert...
[09/05/2006 22:03:38][ PAWS] - PAWS alert skipped
[09/05/2006 22:03:38][ PAWS] - queueing paws alert...
[09/05/2006 22:03:38][ PAWS] - PAWS alert skipped
[09/05/2006 22:03:38][ PAWS] - queueing paws alert...
[09/05/2006 22:03:38][ PAWS] - PAWS alert skipped
[09/05/2006 22:03:38][ PAWS] - queueing paws alert...
[09/05/2006 22:03:38][ PAWS] - PAWS alert skipped
[09/05/2006 22:03:38][ PAWS] - queueing paws alert...
[09/05/2006 22:03:38][ PAWS] - PAWS alert skipped
[09/05/2006 22:03:38][ WKCOM] - >>> EVENT: Type(TDI) Pid(109000) QueryId(0) ActionTaken(ALLOWED) Actor(EMULE.EXE)
[09/05/2006 22:03:38][ WKCOM] - >>> EVENT: Type(TDI) Pid(109000) QueryId(0) ActionTaken(ALLOWED) Actor(EMULE.EXE)
[09/05/2006 22:03:38][ PAWS] - PAWS alert queued
[09/05/2006 22:03:38][ PAWS] - PAWS alert queued
[09/05/2006 22:03:38][ WKCOM] - >>> QUERY: Type(NXD) Pid(200009000) QueryId(282) ActionToTake(QUERY) Actor(EXPLORER.EXE)
[09/05/2006 22:03:38][ WKCOM] - QueryResponse( QueryId=282, policyId=200009000, Allow=1)
[09/05/2006 22:03:38][ WKCOM] - >>> EVENT: Type(NXD) Pid(200009000) QueryId(282) ActionTaken(ALLOWED) Actor(EXPLORER.EXE)
[09/05/2006 22:03:38][ PAWS] - PAWS alert queued
Attached Files
File Type: txt smitfiles.txt (3.1 KB, 3 views)



Last edited by iMagnusX; 05-10-2006 at 04:06 AM.
  #18  
Old 05-10-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hhmm.. it keeps coming back but it is not one of the latest version that needs special removal instructions.. It should just stay gone , and be able to be removed with smitrem..

Download and run the Smitfraud fix from here:

http://siri.urz.free.fr/Fix/SmitfraudFix_En.php

And post back with the C:\rapport.txt log please.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #19  
Old 05-10-2006
Bronze Member
 
Join Date: Mar 2006
Posts: 17
iMagnusX - See this Members User comments on their Profile page
Default

OK here's the smitfraud log, it seems it got a hold of something, and so far, nothing has popped up yet...
Attached Files
File Type: txt rapport.txt (640 Bytes, 2 views)


  #20  
Old 05-11-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Yup , it has indeed deleted acouple of things. Some the same as the smitrem tool deleted everytime but keep coming back , and also some other files from the system32 folder.

Lets run another smitrem scan to see if that still finds anything now.

And what are the remaining problems atm , if any?


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #21  
Old 05-12-2006
Bronze Member
 
Join Date: Mar 2006
Posts: 17
iMagnusX - See this Members User comments on their Profile page
Default

There are no problems now! here's a new smitrem log.
Attached Files
File Type: txt smitfiles.txt (3.1 KB, 3 views)



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 03:59 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top