Generic.pwstealer.77e44459 In Svchost.exe

Hey guys I found out a couple of days ago that i have a keylogger called Generic.PWStealer.77E44459 in svchost.exe in windows/system32. A HiJackThis log is below, and i dont think those "Hosts" should be there should they? :S


Logfile of Trend Micro HijackThis v2.0.2


Scan saved at 3:13:51 AM, on 7/14/2009


Platform: Windows XP SP3 (WinNT 5.01.2600)


MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)


Boot mode: Normal


Running processes:


C:\WINDOWS\System32\smss.exe


C:\WINDOWS\system32\winlogon.exe


C:\WINDOWS\system32\services.exe


C:\WINDOWS\system32\lsass.exe


C:\WINDOWS\system32\svchost.exe


C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe


C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe


C:\WINDOWS\System32\svchost.exe


C:\WINDOWS\system32\svchost.exe


C:\WINDOWS\system32\spoolsv.exe


C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe


C:\Program Files\Java\jre6\bin\jqs.exe


C:\WINDOWS\system32\nvsvc32.exe


C:\WINDOWS\system32\PnkBstrA.exe


C:\WINDOWS\system32\PnkBstrB.exe


C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe


C:\WINDOWS\system32\svchost.exe


C:\WINDOWS\Explorer.EXE


C:\WINDOWS\system32\SearchIndexer.exe


C:\Program Files\Canon\CAL\CALMAIN.exe


C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe


C:\Program Files\VDOTool\TBPanel.exe


C:\Program Files\Java\jre6\bin\jusched.exe


C:\WINDOWS\system32\LVCOMSX.EXE


C:\Program Files\Logitech\Video\LogiTray.exe


C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe


C:\Program Files\Logitech\Video\FxSvr2.exe


C:\WINDOWS\system32\RUNDLL32.EXE


C:\WINDOWS\RTHDCPL.EXE


C:\WINDOWS\system32\ctfmon.exe


C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe


C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe


C:\Program Files\DNA\btdna.exe


C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe


C:\Program Files\Orbitdownloader\orbitdm.exe


C:\Program Files\Windows Desktop Search\WindowsSearch.exe


C:\Program Files\Orbitdownloader\orbitnet.exe


C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe


C:\WINDOWS\system32\svchost.exe


C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\CPSHelpRunner10.exe


C:\Program Files\Windows Live\Contacts\wlcomm.exe


C:\WINDOWS\System32\svchost.exe


C:\Program Files\iPod\bin\iPodService.exe


C:\Program Files\BitDefender\BitDefender 2009\uiscan.exe


C:\Program Files\Steam\UnDeadPatch.exe


C:\Program Files\Steam\Steam.exe


C:\Program Files\Mozilla Firefox\firefox.exe


C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe


C:\WINDOWS\system32\wuauclt.exe


C:\WINDOWS\system32\SearchProtocolHost.exe


C:\Program Files\Trend Micro\HijackThis\HijackThis.exe


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/


O1 - Hosts: 64.233.161.104 localhost


O1 - Hosts: 64.233.161.104 latinhackz.net


O1 - Hosts: 64.233.161.104 gamerztools.net


O1 - Hosts: 64.233.161.104 www.gamerztools.net


O1 - Hosts: 64.233.161.104 http://www.gamerztools.net


O1 - Hosts: 64.233.161.104 http://www.latinhackz.net


O1 - Hosts: 64.233.161.104 www.latinhackz.net


O1 - Hosts: 64.233.161.104 unionforos.com


O1 - Hosts: 64.233.161.104 www.unionforos.com


O1 - Hosts: 64.233.161.104 http://www.unionforos.com


O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll


O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll


O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll


O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)


O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll


O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll


O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll


O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll


O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL (file missing)


O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll


O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll


O3 - Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - (no file)


O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe"


O4 - HKLM\..\Run: [Gainward] C:\Program Files\VDOTool\TBPanel.exe /A


O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup


O4 - HKLM\..\Run: [nwiz] nwiz.exe /install


O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"


O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE


O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe


O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe


O4 - HKLM\..\Run: [bDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"


O4 - HKLM\..\Run: [bitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"


O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"


O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime


O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"


O4 - HKLM\..\Run: [tmp] "C:\DOCUME~1\Admin\LOCALS~1\Temp\tmp\xfirebruter.exe"


O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit


O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE


O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE


O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe


O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background


O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe


O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot


O4 - HKCU\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start


O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun


O4 - HKCU\..\Run: [bitTorrent DNA] "C:\Program Files\DNA\btdna.exe"


O4 - HKCU\..\Run: [VeohPlugin] "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"


O4 - HKCU\..\Run: [steam] "C:\Program Files\Steam\Steam.exe" -silent


O4 - S-1-5-18 Startup: rncsys32.exe (User 'SYSTEM')


O4 - .DEFAULT Startup: rncsys32.exe (User 'Default user')


O4 - Startup: rncsys32.exe


O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE


O4 - Global Startup: Orbit.lnk = C:\Program Files\Orbitdownloader\orbitdm.exe


O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe


O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201


O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204


O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203


O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202


O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000


O8 - Extra context menu item: Open with &ZipScan - C:\PROGRA~1\ZIPSCA~1\zs_ie.htm


O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll


O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll


O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll


O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll


O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll


O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll


O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe


O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe


O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab


O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cab


O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-AU/a-UNO1/GAME_UNO1.cab


O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab


O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab


O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab


O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL


O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe


O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe


O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. http://www.bitdefender.com - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe


O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe


O23 - Service: getPlus® Helper - Unknown owner - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (file missing)


O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe


O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe


O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe


O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe


O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe


O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe


O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe


O23 - Service: Roxio UPnP Renderer 10 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe


O23 - Service: Roxio Upnp Server 10 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 10\RoxioUpnpService10.exe


O23 - Service: LiveShare P2P Server 10 (RoxLiveShare10) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe


O23 - Service: RoxMediaDB10 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe


O23 - Service: Roxio Hard Drive Watcher 10 (RoxWatch10) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe


O23 - Service: TVersityMediaServer - Unknown owner - C:\Program Files\TVersity\Media Server\MediaServer.exe


O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe


--


End of file - 12425 bytes


anyways any help on how to remove this would be appreciated.

post-25479-1247513046_thumb.jpg

Comments

  • HI,


    I'm using Bif defender 12.0.12 anti virus software. When I did deep system scan, my scan result has shown me that below two issues. My system is not able to clean them at all. How to clean these two infected items. Please let me know.


    [system]=]C:\WINDOWS\system32\svchost.exe (full dump) DeepScan:Generic.PWStealer.63BC4717 Disinfect Failed


    [system]=]C:\WINDOWS\system32\svchost.exe (memory dump) Generic.PWStealer.0E96BF1A Disinfect Failed


    Thanks,

  • Alex Stanciu
    Alex Stanciu ✭✭
    edited July 2009

    Hello hellboiy and mkk ,


    Please follow the next link :http://forum.bitdefender.com/index.php?showtopic=14206 and look at the last post. Here , you have the instructions that will help you generate a report with the Avis tool. Please follow these steps and after the bd_sys_log.xml.zip is generated , go to http://www.sendspace.com/ and upload it here . Then reply with the download link . Also , a Deep System Scan report will help us , so we would like you to upload a copy of this report as well . These files will be analyzed by our Virus Analysis team , as soon as you post your reply .


    Thank you .

  • Hello Alex,


    I have downloaded that AVIS and generated a system log file. As per your instructions, I have uploaded that file to sendspace website. Please use the below link to download that file.


    http://www.sendspace.com/file/1ghf3s


    Also I'm attaching the deep system scan report I have generated today. Please let me know if I need to provide anything else.


    Thanks,


    mkk.

    /applications/core/interface/file/attachment.php?id=5348" data-fileid="5348" rel="">1247818954_1_02.xml

  • hellboiy
    edited July 2009

    Hey very sorry for the late reply, here is the link:


    http://www.sendspace.com/file/whvih9


    I will post the deep scan when it is done if required. The last few times i did a deep scan it didn't finish :S hard to explain but if it happens again ill take a screen shot. Thanks

  • Hello hellboiy and mkk ,


    We have sent the files to our Virus Lab for analysis purposes and we will contact you with more information once this process has been successfully completed .


    Thank you .