Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.When posting your problem, do not run and post a ComboFix logs. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.
To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.
![]() ![]() |
Jan 10 2009, 06:09 PM
Post
#1
|
|
![]() New Member ![]() Group: Members Posts: 5 Joined: 10-January 09 Member No.: 280,929 |
Please help. I am a newbie at this. |
|
|
|
Jan 10 2009, 07:00 PM
Post
#2
|
|
![]() To INSANITY and BEYOND !! ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 21,869 Joined: 10-September 04 From: NJ USA Member No.: 2,608 |
Hi and welcome. Yes you should run this MBam scan next.
Please download Malwarebytes Anti-Malware and save it to your desktop. alternate download link 1 alternate download link 2
-------------------- Can you spare some PC cycles to help FIND A CURE .. BC FOLDING TEAM Click me /info..
ThoughtVent a goodplace to discuss.<<>>>Staying Updated Calendar of Updates. For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear.... Become a BleepingComputer fan: Facebook |
|
|
|
Jan 10 2009, 07:07 PM
Post
#3
|
|
![]() New Member ![]() Group: Members Posts: 5 Joined: 10-January 09 Member No.: 280,929 |
This is what came up in the scan.
Malwarebytes' Anti-Malware 1.32 Database version: 1638 Windows 5.1.2600 Service Pack 3 2009-01-10 18:03:57 mbam-log-2009-01-10 (18-03-57).txt Scan type: Quick Scan Objects scanned: 74979 Time elapsed: 41 minute(s), 17 second(s) Memory Processes Infected: 1 Memory Modules Infected: 5 Registry Keys Infected: 26 Registry Values Infected: 4 Registry Data Items Infected: 2 Folders Infected: 3 Files Infected: 21 Memory Processes Infected: C:\Program Files\GetModule\GetModule33.exe (Trojan.Agent) -> Unloaded process successfully. Memory Modules Infected: C:\WINDOWS\SYSTEM32\nqlponss.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\SYSTEM32\qoMffCus.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\SYSTEM32\dwrwlnuy.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\SYSTEM32\wrbzky.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\SYSTEM32\khfCUnNh.dll (Trojan.Vundo) -> Delete on reboot. Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{98e0112d-7a17-4eed-8246-1a649ed2e917} (Trojan.Vundo.H) -> Delete on reboot. HKEY_CLASSES_ROOT\CLSID\{98e0112d-7a17-4eed-8246-1a649ed2e917} (Trojan.Vundo.H) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fcd9ef91-085f-4afc-8c5c-b3c4929c3925} (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{fcd9ef91-085f-4afc-8c5c-b3c4929c3925} (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{98e0112d-7a17-4eed-8246-1a649ed2e917} (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{fcd9ef91-085f-4afc-8c5c-b3c4929c3925} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\khfcunnh (Trojan.Vundo) -> Delete on reboot. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4cb8f4b4-5f66-4d9e-bc3b-184596a58824} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\icheck (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\GetModule (Adware.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll (Adware.Minibug) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Extensions\{59a40ac9-e67d-4155-b31d-4b7330fcd2d6} (Adware.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Delete on reboot. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\getmodule33 (Trojan.Agent) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\qomffcus -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\qomffcus -> Delete on reboot. Folders Infected: C:\Program Files\iCheck (Trojan.Agent) -> Quarantined and deleted successfully. C:\Program Files\GetModule (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\Drew\Application Data\GetModule (Trojan.Agent) -> Quarantined and deleted successfully. Files Infected: C:\WINDOWS\SYSTEM32\qoMffCus.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\SYSTEM32\suCffMoq.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\SYSTEM32\suCffMoq.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\SYSTEM32\wrbzky.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\SYSTEM32\aabmbzjz.dllbox (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\SYSTEM32\nqlponss.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\SYSTEM32\ssnoplqn.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\SYSTEM32\dwrwlnuy.dll (Trojan.Vundo) -> Delete on reboot. C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll (Adware.Minibug) -> Quarantined and deleted successfully. C:\WINDOWS\SYSTEM32\khfCUnNh.dll (Trojan.Vundo) -> Delete on reboot. C:\Documents and Settings\Drew\Local Settings\Temporary Internet Files\Content.IE5\E7SVOHM1\index[1] (Trojan.Vundo) -> Quarantined and deleted successfully. C:\Documents and Settings\Drew\Local Settings\Temporary Internet Files\Content.IE5\QLENQVI9\upd105320[1] (Trojan.Vundo) -> Quarantined and deleted successfully. C:\Program Files\iCheck\Uninstall.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Program Files\GetModule\GetModule33.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\Drew\Application Data\GetModule\dicik.gz (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\Drew\Application Data\GetModule\kwdik.gz (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\Drew\Application Data\GetModule\ofadik.gz (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\SYSTEM32\wpv661231601797.cpx (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\SYSTEM32\~.exe (Trojan.Downloader) -> Quarantined and deleted successfully. C:\WINDOWS\SYSTEM32\cbXOHBtr.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\SYSTEM32\winlogon.ini (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully. |
|
|
|
Jan 10 2009, 07:25 PM
Post
#4
|
|
![]() New Member ![]() Group: Members Posts: 5 Joined: 10-January 09 Member No.: 280,929 |
I re-started the computer after the scan as prompted. I have been using the internet without any pop-ups sense then. Running that scan has defiantly fixed something. :D
|
|
|
|
Jan 10 2009, 08:15 PM
Post
#5
|
|
![]() To INSANITY and BEYOND !! ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 21,869 Joined: 10-September 04 From: NJ USA Member No.: 2,608 |
Hello,this machine is loaded and will take a few scans to clean.
We will do these 3 next: ATF: Please download ATF Cleaner by Atribune & save it to your desktop.
SAS: Please download and scan with SUPERAntiSpyware Free
Scan with SUPERAntiSpyware as follows:
Now MBAm again like this: Open MBAM and click Update tab, select Check for Updates,when done click Scanner tab,select FULL scan and scan. After scan click Remove Selected, Post new scan log and Reboot. -------------------- Can you spare some PC cycles to help FIND A CURE .. BC FOLDING TEAM Click me /info..
ThoughtVent a goodplace to discuss.<<>>>Staying Updated Calendar of Updates. For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear.... Become a BleepingComputer fan: Facebook |
|
|
|
Jan 11 2009, 11:08 AM
Post
#6
|
|
![]() New Member ![]() Group: Members Posts: 5 Joined: 10-January 09 Member No.: 280,929 |
SUPERAntiSpyware Scan Log
http://www.superantispyware.com Generated 01/11/2009 at 09:56 AM Application Version : 4.24.1004 Core Rules Database Version : 3705 Trace Rules Database Version: 1680 Scan type : Quick Scan Total Scan Time : 00:29:09 Memory items scanned : 159 Memory threats detected : 0 Registry items scanned : 507 Registry threats detected : 8 File items scanned : 12606 File threats detected : 6 Adware.eXact Advertising/eXact Search Bar HKU\S-1-5-21-3529755120-707887090-1196663076-1009\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser#{224530A0-C9CB-4AEE-9C0F-54AC1B533211} Rogue.Component/Trace HKLM\Software\Microsoft\D4FDFA0B HKLM\Software\Microsoft\D4FDFA0B#d4fdfa0b HKLM\Software\Microsoft\D4FDFA0B#Version HKLM\Software\Microsoft\D4FDFA0B#d4fd578b HKLM\Software\Microsoft\D4FDFA0B#d4fd3e6e HKU\S-1-5-21-3529755120-707887090-1196663076-1009\Software\Microsoft\CS41275 HKU\S-1-5-21-3529755120-707887090-1196663076-1009\Software\Microsoft\FIAS4018 Adware.OuterInfo-Installer C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\OUTERINFO\OIUNINSTALLER.EXE.VIR Trojan.Unknown Origin C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\WNSTSSV.EXE.VIR C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\WNSTSTR.EXE.VIR Adware.Vundo Variant/Rel C:\WINDOWS\SYSTEM32\AYADD.INI C:\WINDOWS\SYSTEM32\YCCDD.INI Trojan.Fake-Drop/Gen C:\WINDOWS\ZSERV.DLL |
|
|
|
Jan 11 2009, 02:04 PM
Post
#7
|
|
![]() New Member ![]() Group: Members Posts: 5 Joined: 10-January 09 Member No.: 280,929 |
Malwarebytes' Anti-Malware 1.32
Database version: 1643 Windows 5.1.2600 Service Pack 3 2009-01-11 13:01:32 mbam-log-2009-01-11 (13-01-32).txt Scan type: Full Scan (A:\|C:\|D:\|E:\|) Objects scanned: 142217 Time elapsed: 1 hour(s), 53 minute(s), 7 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) |
|
|
|
Jan 11 2009, 02:47 PM
Post
#8
|
|
![]() To INSANITY and BEYOND !! ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 21,869 Joined: 10-September 04 From: NJ USA Member No.: 2,608 |
Good call as that was what I wanted next. Any more signs of infection?
-------------------- Can you spare some PC cycles to help FIND A CURE .. BC FOLDING TEAM Click me /info..
ThoughtVent a goodplace to discuss.<<>>>Staying Updated Calendar of Updates. For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear.... Become a BleepingComputer fan: Facebook |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 21st November 2009 - 07:28 PM |