Results 1 to 3 of 3

Thread: services.exe sends out data to suspect IP (208.66.195.248)

  1. #1
    nakedlunch Guest

    Default services.exe sends out data to suspect IP (208.66.195.248)

    I've been notified by my ISP that spam originated from my IP. When I investigated, I found that Services and Controller app (services.exe) sends out heavy traffic to suspect IPs (HTTP 208.66.195.248, and an SMTP IP). When I block that process in Zone Alarm, spam complaints stop coming.

    I can keep that service blocked permanently, but that won't remove the trojan. AVG, Spybot S&D and Ad-Aware all run daily with updated records, but find nothing. Googling is of no help as everyone reports services.exe as a safe Windows service. I've tried other miracle cures, such as Security Task Manager, none of which helped.

    I suspect that smss.exe and/or csrss.exe might have been hijacked, but I don't know how to repair them. I've included a report from Hijack This in the hope that someone could identify the culprit. My last remaining resort is to do a clean re-install of Windows.

    Thanks for your help.


    Logfile of HijackThis v1.99.1
    Scan saved at 18:57:32, on 27/09/2006
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\UTILIT~1\AVGFRE~1\avgamsvr.exe
    C:\UTILIT~1\AVGFRE~1\avgupsvc.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\Explorer.EXE
    C:\UTILIT~1\AVGFRE~1\avgcc.exe
    C:\utilities\ZoneAlarm\zlclient.exe
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\WINDOWS\System32\RUNDLL32.EXE
    C:\WINDOWS\System32\wdfmgr.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\utilities\SpeedFan\speedfan.exe
    C:\multimedia\SageTV\SageTV\SageTV.exe
    C:\multimedia\WinTV\Ir.exe
    C:\internet\Xnews\XNEWS.EXE
    C:\WINDOWS\system32\mstsc.exe
    C:\internet\firefox\firefox.exe
    C:\utilities\Hijackthis\HijackThis.exe

    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
    O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
    O4 - HKLM\..\Run: [AVG7_CC] C:\UTILIT~1\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\utilities\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [SpybotSnD] "C:\utilities\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autofix /autoclose /waitstart
    O4 - HKLM\..\Run: [SageTV] "C:\multimedia\SageTV\SageTV\SageTV.exe&qu ot; -startup
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
    O4 - Startup: Shortcut to speedfan.lnk = C:\utilities\SpeedFan\speedfan.exe
    O4 - Global Startup: AutoStart IR.lnk = C:\multimedia\WinTV\Ir.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_12\bin\npjpi142_12.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_12\bin\npjpi142_12.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O20 - Winlogon Notify: winjyg32 - winjyg32.dll (file missing)
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\UTILIT~1\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\UTILIT~1\AVGFRE~1\avgupsvc.exe
    O23 - Service: Logitech Bluetooth Service (LBTServ) - Unknown owner - C:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE (file missing)
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

  2. #2
    nakedlunch Guest

    Default Re: services.exe sends out data to suspect IP (208.66.195.248)

    I fixed the problem. I installed Norton antivirus (which tried to convince me to remove Zone Alarm first), then scanned my computer. It detected and removed the following viruses:

    - Backdoor.Rustock.B
    - Infostealer
    - Downloader (two versions)

    I then completely cleaned out Norton (which I find too invasive and overbearing). I'm seriously disenchanted with AVG, which never even detected the viruses, let alone removed them.


    Nakedlunch

  3. #3

    Default Re: services.exe sends out data to suspect IP (208.66.195.248)

    I'm glad you fixed your problem. AVG is just ok a few of the better ones are Kaspersky 6.0 which I use ,and NOD32 .
    Take care

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •