Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.When posting your problem, do not run and post a ComboFix logs. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.
To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.
![]() ![]() |
Nov 19 2008, 08:55 PM
Post
#1
|
|
![]() Forum Addict ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 1,384 Joined: 21-September 08 From: NeverLand Member No.: 240,362 |
So my question is, should I be concerned about this program? If it is malicious, how dangerous is it? I did some reading, it is contradictory, some says its spyware, some says its safe. I'm getting quite confused. Thanks in advance, ~Jordan (xBL!NDx) This post has been edited by xblindx: Nov 19 2008, 08:55 PM -------------------- ![]() Please help people in need for free by visiting Free Rice Increase the security of your computer by using SpywareBlaster Please use the button to post a reply. Do not use the button |
|
|
|
Nov 20 2008, 08:05 PM
Post
#2
|
|
![]() BC 1st Responder ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 8,281 Joined: 21-October 04 From: South Carolina - USA Member No.: 3,905 |
Hi Jordan,
It never hurts to do a quick scan. Please download Malwarebytes Anti-Malware and save it to your desktop. alternate download link 1 alternate download link 2
-- If MBAM encounters a file that is difficult to remove, you may be asked to reboot your computer so it can proceed with the disinfection process. Regardless if prompted to restart the computer or not, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware. -- MBAM may make changes to your registry as part of its disinfection routine. If you're using other security programs that detect registry changes (like Spybot's Teatimer), they may interfere with the fix or alert you after scanning with MBAM. Please disable such programs until disinfection is complete or permit them to allow the changes. -------------------- "In a world where you can be anything, be yourself." ~ unknown Become a BleepingComputer fan: Facebook |
|
|
|
Nov 20 2008, 08:19 PM
Post
#3
|
|
![]() Forum Addict ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 1,384 Joined: 21-September 08 From: NeverLand Member No.: 240,362 |
I've already scanned with MBAM, Avira and am currently scanning with SB:S&D.scans have been clean so far.
-------------------- ![]() Please help people in need for free by visiting Free Rice Increase the security of your computer by using SpywareBlaster Please use the button to post a reply. Do not use the button |
|
|
|
Nov 20 2008, 08:22 PM
Post
#4
|
|
![]() BC 1st Responder ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 8,281 Joined: 21-October 04 From: South Carolina - USA Member No.: 3,905 |
What version of Windows?
-------------------- "In a world where you can be anything, be yourself." ~ unknown Become a BleepingComputer fan: Facebook |
|
|
|
Nov 21 2008, 07:20 AM
Post
#5
|
|
![]() Forum Addict ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 1,384 Joined: 21-September 08 From: NeverLand Member No.: 240,362 |
XP Home Edition. SP3
-------------------- ![]() Please help people in need for free by visiting Free Rice Increase the security of your computer by using SpywareBlaster Please use the button to post a reply. Do not use the button |
|
|
|
Nov 21 2008, 01:09 PM
Post
#6
|
|
![]() BC 1st Responder ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 8,281 Joined: 21-October 04 From: South Carolina - USA Member No.: 3,905 |
You can try SDFix
Please print out and follow these instructions: "How to use SDFix". <- This program is for Windows 2000/XP ONLY. When using this tool, you must use the Administrator's account or an account with "Administrative rights"
-------------------- "In a world where you can be anything, be yourself." ~ unknown Become a BleepingComputer fan: Facebook |
|
|
|
Nov 21 2008, 03:09 PM
Post
#7
|
|
![]() Forum Addict ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 1,384 Joined: 21-September 08 From: NeverLand Member No.: 240,362 |
You do know that we aren't sure if this is an infection.....should I still run SDfix if I am not 100% sure it is an infection?
-------------------- ![]() Please help people in need for free by visiting Free Rice Increase the security of your computer by using SpywareBlaster Please use the button to post a reply. Do not use the button |
|
|
|
Nov 21 2008, 03:54 PM
Post
#8
|
|
![]() BC 1st Responder ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 8,281 Joined: 21-October 04 From: South Carolina - USA Member No.: 3,905 |
I have run it on several of my computers without issue - a few test computers with no signs of infection.
If you feel good that there isn't any signs of infection from your scans, you are probably good. -------------------- "In a world where you can be anything, be yourself." ~ unknown Become a BleepingComputer fan: Facebook |
|
|
|
Nov 21 2008, 04:14 PM
Post
#9
|
|
![]() Forum Addict ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 1,384 Joined: 21-September 08 From: NeverLand Member No.: 240,362 |
I ran it, and wow, it found 2 trojans
SDFix: Version 1.240 Run by Jordan on Fri 11/21/2008 at 03:28 PM Microsoft Windows XP [Version 5.1.2600] Running From: C:\sdfix Checking Services : Restoring Default Security Values Restoring Default Hosts File Rebooting Checking Files : Trojan Files Found: C:\WINDOWS\SYSTEM32\MSNNAMES.EXE - Deleted C:\WINDOWS\ORUN32.EXE - Deleted Removing Temp Files ADS Check : Final Check : catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-11-21 15:58:23 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden services & system hive ... scanning hidden registry entries ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 Remaining Services : Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader" "C:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe"="C:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe:*:Enabled:ET" "C:\\Program Files\\Steam\\SteamApps\\eyeblood\\counter-strike\\hl.exe"="C:\\Program Files\\Steam\\SteamApps\\eyeblood\\counter-strike\\hl.exe:*:Enabled:Half-Life Launcher" "C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus" "C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"="C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe:*:Enabled:Remote Assistance - Windows Messenger and Voice" "C:\\Program Files\\Xfire\\Xfire.exe"="C:\\Program Files\\Xfire\\Xfire.exe:*:Enabled:Xfire" "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire" "C:\\Program Files\\Steam\\SteamApps\\eyeblood\\counter-strike source\\hl2.exe"="C:\\Program Files\\Steam\\SteamApps\\eyeblood\\counter-strike source\\hl2.exe:*:Enabled:hl2" "C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox" "C:\\Program Files\\Avira\\AntiVir PersonalEdition Classic\\avcenter.exe"="C:\\Program Files\\Avira\\AntiVir PersonalEdition Classic\\avcenter.exe:*:Enabled:Start AntiVir PersonalEdition Classic" "C:\\Program Files\\Warcraft III\\War3.exe"="C:\\Program Files\\Warcraft III\\War3.exe:*:Enabled:Warcraft III" "C:\\Program Files\\Warcraft III\\Warcraft III.exe"="C:\\Program Files\\Warcraft III\\Warcraft III.exe:*:Enabled:Warcraft III" "C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Enabled:RealPlayer" "C:\\Program Files\\Steam\\steamapps\\eyeblood\\day of defeat source\\hl2.exe"="C:\\Program Files\\Steam\\steamapps\\eyeblood\\day of defeat source\\hl2.exe:*:Enabled:hl2" "C:\\Program Files\\AIM6\\aim6.exe"="C:\\Program Files\\AIM6\\aim6.exe:*:Enabled:AIM" "C:\\WINDOWS\\system32\\LEXPPS.EXE"="C:\\WINDOWS\\system32\\LEXPPS.EXE:*:Disabled:LEXPPS.EXE" "C:\\Program Files\\utorrent\\utorrent.exe"="C:\\Program Files\\utorrent\\utorrent.exe:*:Disabled:ęTorrent" "C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Disabled:Bonjour" "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:America Online 9.0" "C:\\Program Files\\Common Files\\AOL\\1124492134\\ee\\AOLServiceHost.exe"="C:\\Program Files\\Common Files\\AOL\\1124492134\\ee\\AOLServiceHost.exe:*:Enabled:AOL Services" "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader" "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:MSN Messenger 7.5" "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe:*:Enabled:AOL" "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL" "C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" Remaining Files : File Backups: - C:\SDFix\backups\backups.zip Files with Hidden Attributes : Wed 1 Feb 2006 1,185 A..H. --- "C:\Documents and Settings\Shirley\IPH.BAK" Thu 8 Mar 2007 258,560 A..H. --- "C:\Program Files\Adobe\upx.exe" Wed 22 Oct 2008 949,072 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\advcheck.dll" Mon 15 Sep 2008 1,562,960 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll" Mon 7 Jul 2008 1,429,840 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe" Mon 7 Jul 2008 4,891,472 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" Tue 16 Sep 2008 1,833,296 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" Wed 22 Oct 2008 962,896 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\Tools.dll" Mon 19 Sep 2005 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak" Thu 16 Sep 2004 1,949,696 ...HR --- "C:\Program Files\Microsoft Works Suite 2005\Setup\LAUNCHER.EXE" Thu 16 Sep 2004 53,760 ...HR --- "C:\Program Files\Microsoft Works Suite 2005\Setup\MNYINSTA.DLL" Thu 16 Sep 2004 94,208 ...HR --- "C:\Program Files\Microsoft Works Suite 2005\Setup\RMVSUITE.EXE" Thu 16 Sep 2004 35,328 ...HR --- "C:\Program Files\Microsoft Works Suite 2005\Setup\SETUPLNG.DLL" Thu 16 Sep 2004 20,480 ...HR --- "C:\Program Files\Microsoft Works Suite 2005\Setup\UNREGWTR.EXE" Thu 14 Dec 2006 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv03.tmp" Wed 29 Mar 2006 2,461,696 A..H. --- "C:\Documents and Settings\Jordan\Application Data\U3\temp\Launchpad Removal.exe" Finished! Here is the entry from the TeaTimer log: QUOTE 11/21/2008 4:08:02 PM Allowed (based on user decision) value "load" (new data: "") added in NT startup!
This post has been edited by xblindx: Nov 21 2008, 04:16 PM -------------------- ![]() Please help people in need for free by visiting Free Rice Increase the security of your computer by using SpywareBlaster Please use the button to post a reply. Do not use the button |
|
|
|
Nov 21 2008, 07:46 PM
Post
#10
|
|
![]() BC 1st Responder ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 8,281 Joined: 21-October 04 From: South Carolina - USA Member No.: 3,905 |
Please update and rerun malwarebytes. Let's see if we uncovered anything..
-------------------- "In a world where you can be anything, be yourself." ~ unknown Become a BleepingComputer fan: Facebook |
|
|
|
Nov 21 2008, 10:38 PM
Post
#11
|
|
![]() Forum Addict ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 1,384 Joined: 21-September 08 From: NeverLand Member No.: 240,362 |
Yes sir, log coming up shortly.
-------------------- ![]() Please help people in need for free by visiting Free Rice Increase the security of your computer by using SpywareBlaster Please use the button to post a reply. Do not use the button |
|
|
|
Nov 21 2008, 11:52 PM
Post
#12
|
|
![]() Forum Addict ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 1,384 Joined: 21-September 08 From: NeverLand Member No.: 240,362 |
Malwarebytes' Anti-Malware 1.30
Database version: 1415 Windows 5.1.2600 Service Pack 3 11/21/2008 11:50:53 PM mbam-log-2008-11-21 (23-50-53).txt Scan type: Quick Scan Objects scanned: 62720 Time elapsed: 17 minute(s), 8 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) -------------------- ![]() Please help people in need for free by visiting Free Rice Increase the security of your computer by using SpywareBlaster Please use the button to post a reply. Do not use the button |
|
|
|
Nov 23 2008, 05:49 PM
Post
#13
|
|
![]() BC 1st Responder ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 8,281 Joined: 21-October 04 From: South Carolina - USA Member No.: 3,905 |
Sorry about the missed reply xblindx
Lets see if anything is left out there. Please download ATF Cleaner by Atribune & save it to your desktop. alternate download link DO NOT use yet. Please download and install SUPERAntiSpyware Free
Double-click ATF-Cleaner.exe to run the program.
ATF-Cleaner must be "Run as an Administrator". Scan with SUPERAntiSpyware as follows:
-------------------- "In a world where you can be anything, be yourself." ~ unknown Become a BleepingComputer fan: Facebook |
|
|
|
Nov 23 2008, 05:53 PM
Post
#14
|
|
![]() Forum Addict ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 1,384 Joined: 21-September 08 From: NeverLand Member No.: 240,362 |
I will use CCleaner for my temporary cleaning. I will run SAS whenever I am at school (tomorrow) as I already have it and run it occasionally with MBAM and SB S&D.
-------------------- ![]() Please help people in need for free by visiting Free Rice Increase the security of your computer by using SpywareBlaster Please use the button to post a reply. Do not use the button |
|
|
|
Nov 23 2008, 06:36 PM
Post
#15
|
|
![]() BC 1st Responder ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 8,281 Joined: 21-October 04 From: South Carolina - USA Member No.: 3,905 |
Ok... let us know...
-------------------- "In a world where you can be anything, be yourself." ~ unknown Become a BleepingComputer fan: Facebook |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 4th July 2009 - 08:30 PM |