Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Would Like Some Help Please


  • Please log in to reply
17 replies to this topic

#1 Randomguy68

Randomguy68

  • Members
  • 93 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:55 AM

Posted 28 July 2008 - 02:28 PM

I'm new to this and a total newb. :thumbsup:
My computer is infected with Adware.generic and trojans that keep coming back each time I scan with MBAM and AVG.
It says Adware.generic is located HKLM\SOFTWARE\Classes\WR and HKLM\SOFTWARE\Microsoft\CurrentVersion\Run\\Runner1
and the trojans scanned by MBAM also keep returning and shows up in the same spot as Adware.generic and recently MBAM scanned it in a new place c:\\WINDOWS\17PHOLMES1001186.exe and c:\\WINDOWS\mrofinu1001186.exe

Can you please help me? :flowers:

Edited by Randomguy68, 28 July 2008 - 02:59 PM.

SPYWARRRRRRRRRRRRRE!!!!

BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 72,912 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:08:55 AM

Posted 28 July 2008 - 03:00 PM

Hello can you post the latest MBam log please.
Also try another scan. Run this from safe mod after install and updating.
Are you running XP, McCaffe or spyBot?

Please download ATF Cleaner by Atribune & save it to your desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main "Select Files to Delete" choose: Select All.
  • Click the Empty Selected button.
  • If you use Firefox browser click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
    If you would like to keep your saved passwords, please click No at the prompt.
  • If you use Opera browser click Opera at the top and choose: Select All
  • Click the Empty Selected button.
    If you would like to keep your saved passwords, please click No at the prompt.
  • Click Exit on the Main menu to close the program.
Note: On Vista, "Windows Temp" is disabled. To empty "Windows Temp" ATF-Cleaner must be "Run as an Administrator".

NEXT:
Download and scan with SUPERAntiSpyware Free for Home Users
  • Double-click SUPERAntiSpyware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)
  • Under "Configuration and Preferences", click the Preferences button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen.
  • Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan.
  • Click "Next" to start the scan. Please be patient while it scans your computer.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes".
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply.
  • Click Close to exit the program.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 Randomguy68

Randomguy68
  • Topic Starter

  • Members
  • 93 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:55 AM

Posted 28 July 2008 - 03:13 PM

Malwarebytes' Anti-Malware 1.23
Database version: 989
Windows 5.1.2600 Service Pack 1

3:12:03 PM 7/28/2008
mbam-log-7-28-2008 (15-12-03).txt

Scan type: Full Scan (C:\|G:\|)
Objects scanned: 57704
Time elapsed: 8 minute(s), 3 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\WR (Malware.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\runner1 (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\ThienTue\Local Settings\Temporary Internet Files\Content.IE5\GTU7WD23\17PHolmes[1].cmt (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\mrofinu1001186.exe (Trojan.Agent) -> Delete on reboot.

Ah and I am running on XP. :thumbsup:
SPYWARRRRRRRRRRRRRE!!!!

#4 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 72,912 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:08:55 AM

Posted 28 July 2008 - 03:18 PM

Thanks, Also Reboot (if you havn't)the PC to finish removal of some malware MBam found. Update as it is up ver. 1002 or something now . Rescan and post that new log also. Just need a quoick scan with MBam now.

Edited by boopme, 28 July 2008 - 03:19 PM.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#5 Randomguy68

Randomguy68
  • Topic Starter

  • Members
  • 93 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:55 AM

Posted 28 July 2008 - 04:02 PM

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 07/28/2008 at 03:44 PM

Application Version : 4.15.1000

Core Rules Database Version : 3519
Trace Rules Database Version: 1509

Scan type : Complete Scan
Total Scan Time : 00:13:35

Memory items scanned : 345
Memory threats detected : 1
Registry items scanned : 3937
Registry threats detected : 14
File items scanned : 13444
File threats detected : 27

Trojan.Downloader-Gen/MROFIN
C:\WINDOWS\MROFINU1001186.EXE
C:\WINDOWS\MROFINU1001186.EXE
[runner1] C:\WINDOWS\MROFINU1001186.EXE
C:\WINDOWS\MROFINU1001186.EXE.TMP

Adware.SpeedRunner
[SpeedRunner] C:\WINDOWS\SYSTEM32\CONFIG\SYSTEMPROFILE\APPLICATION DATA\SPEEDRUNNER\SPEEDRUNNER.EXE
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEMPROFILE\APPLICATION DATA\SPEEDRUNNER\SPEEDRUNNER.EXE
[SpeedRunner] C:\WINDOWS\SYSTEM32\CONFIG\SYSTEMPROFILE\APPLICATION DATA\SPEEDRUNNER\SPEEDRUNNER.EXE
HKU\.DEFAULT\Software\SpeedRunner
HKU\S-1-5-18\Software\SpeedRunner
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run#SpeedRunner [ C:\WINDOWS\system32\config\systemprofile\Application Data\SpeedRunner\SpeedRunner.exe ]
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run#SpeedRunner [ C:\WINDOWS\system32\config\systemprofile\Application Data\SpeedRunner\SpeedRunner.exe ]
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run#SfKg6wIP [ C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\tbeqir.exe ]
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run#SfKg6wIP [ C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\tbeqir.exe ]
C:\SYSTEM VOLUME INFORMATION\_RESTORE{0D1D0EBD-9E45-441C-A107-1016F05EAC0F}\RP164\A0096190.EXE

Trojan.Dropper/Gen-Packed
[SfKg6wIP] C:\WINDOWS\SYSTEM32\CONFIG\SYSTEMPROFILE\APPLICATION DATA\MICROSOFT\TBEQIR.EXE
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEMPROFILE\APPLICATION DATA\MICROSOFT\TBEQIR.EXE
[SfKg6wIP] C:\WINDOWS\SYSTEM32\CONFIG\SYSTEMPROFILE\APPLICATION DATA\MICROSOFT\TBEQIR.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{0D1D0EBD-9E45-441C-A107-1016F05EAC0F}\RP164\A0096191.EXE
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEMPROFILE\APPLICATION DATA\SPEEDRUNNER\SRUNINSTALL.EXE

Trojan.DNSChanger-Codec
HKU\.DEFAULT\Software\GetPack
HKU\S-1-5-18\Software\GetPack

Trojan.Downloader-Gen/RetAd
HKLM\Software\Microsoft\Windows\CurrentVersion\Run#runner1 [ C:\WINDOWS\mrofinu1001186.exe 61A847B5BBF72813329B39577AFF01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310 ]

Trojan.Vundo-Variant/F
C:\WINDOWS\SYSTEM32\AZIPCONTMN.DLL
C:\WINDOWS\SYSTEM32\SYSFOLDERAZIPCNT.DLL

Adware.Tracking Cookie
C:\WINDOWS\system32\config\systemprofile\Cookies\system@ad.outerinfoads[2].txt

Adware.ClickSpring
C:\WINDOWS\SYSTEM32\?YSTEM32\?SRSS.EXE

Unclassified.SpywareBot (Not A Threat)
G:\NEW FOLDER (3)\NEW FOLDER (2)\NEW FOLDER\SETUP.EXE
G:\NEW FOLDER (3)\NEW FOLDER (2)\NEW FOLDER (2)\SETUP.EXE
G:\NEW FOLDER (3)\NEW FOLDER (2)\SETUP.EXE

Trace.Known Threat Sources
C:\Documents and Settings\ThienTue\Local Settings\Temporary Internet Files\Content.IE5\GTU7WD23\CAHA3QI3.htm
C:\Documents and Settings\ThienTue\Local Settings\Temporary Internet Files\Content.IE5\GTU7WD23\17PHolmes[1].cmt
C:\Documents and Settings\ThienTue\Local Settings\Temporary Internet Files\Content.IE5\C52F4PEZ\retadpu[1].htm
C:\Documents and Settings\ThienTue\Local Settings\Temporary Internet Files\Content.IE5\0D274T6V\CAME1XEW.htm
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\WH4PI1YZ\retadpu[1].htm
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\01CFYX4L\retadpu[2].htm
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\GHI5Q9MB\mrofinu[1].zip
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\01CFYX4L\retadpu[1].htm
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\GHI5Q9MB\retadpu[1].htm
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\WH4PI1YZ\CA0DIZ8D.htm
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\WH4PI1YZ\17PHolmes[2].cmt
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\WH4PI1YZ\retadpu[2].htm
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QZS72DSH\CAAT4ERE.htm

That is the antispyware

and this is the MBAM again, it didn't change I think

Malwarebytes' Anti-Malware 1.23
Database version: 989
Windows 5.1.2600 Service Pack 1

4:01:26 PM 7/28/2008
mbam-log-7-28-2008 (16-01-26).txt

Scan type: Quick Scan
Objects scanned: 37817
Time elapsed: 2 minute(s), 55 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\WR (Malware.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\runner1 (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\ThienTue\Local Settings\Temporary Internet Files\Content.IE5\0D274T6V\17PHolmes[1].cmt (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\mrofinu1001186.exe (Trojan.Agent) -> Delete on reboot.
:thumbsup:
SPYWARRRRRRRRRRRRRE!!!!

#6 Randomguy68

Randomguy68
  • Topic Starter

  • Members
  • 93 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:55 AM

Posted 28 July 2008 - 05:16 PM

Ah forgot to update!! heres MBAM after update :thumbsup:
Malwarebytes' Anti-Malware 1.23
Database version: 1002
Windows 5.1.2600 Service Pack 1

5:09:54 PM 7/28/2008
mbam-log-7-28-2008 (17-09-54).txt

Scan type: Quick Scan
Objects scanned: 38187
Time elapsed: 5 minute(s), 56 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\WR (Malware.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\runner1 (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\ThienTue\Local Settings\Temporary Internet Files\Content.IE5\C52F4PEZ\17PHolmes[1].cmt (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\mrofinu1001186.exe (Trojan.Agent) -> Delete on reboot.
SPYWARRRRRRRRRRRRRE!!!!

#7 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 72,912 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:08:55 AM

Posted 29 July 2008 - 01:23 PM

This is good... One more update ,scan and log may be the winning ticket,
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#8 Randomguy68

Randomguy68
  • Topic Starter

  • Members
  • 93 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:55 AM

Posted 29 July 2008 - 02:35 PM

Malwarebytes' Anti-Malware 1.23
Database version: 1008
Windows 5.1.2600 Service Pack 1

2:35:04 PM 7/29/2008
mbam-log-7-29-2008 (14-35-04).txt

Scan type: Quick Scan
Objects scanned: 38275
Time elapsed: 11 minute(s), 54 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\ThienTue\Local Settings\Temporary Internet Files\Content.IE5\GXEB8DIN\17PHolmes[1].cmt (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\mrofinu1001186.exe (Trojan.Agent) -> Quarantined and deleted successfully.
SPYWARRRRRRRRRRRRRE!!!!

#9 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 72,912 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:08:55 AM

Posted 29 July 2008 - 03:08 PM

So how is it now? Run it again let's get all zero's... :thumbsup:
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#10 Randomguy68

Randomguy68
  • Topic Starter

  • Members
  • 93 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:55 AM

Posted 30 July 2008 - 06:33 AM

Malwarebytes' Anti-Malware 1.23
Database version: 1008
Windows 5.1.2600 Service Pack 1

6:32:45 AM 7/30/2008
mbam-log-7-30-2008 (06-32-45).txt

Scan type: Quick Scan
Objects scanned: 38349
Time elapsed: 8 minute(s), 10 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
C:\WINDOWS\mrofinu1001186.exe (Trojan.Agent) -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\WR (Malware.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\runner1 (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\mrofinu.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\mrofinu1001186.exe (Trojan.Agent) -> Quarantined and deleted successfully.
SPYWARRRRRRRRRRRRRE!!!!

#11 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 72,912 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:08:55 AM

Posted 30 July 2008 - 10:03 AM

Almost there. I would run the MBam and Super again.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#12 Randomguy68

Randomguy68
  • Topic Starter

  • Members
  • 93 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:55 AM

Posted 31 July 2008 - 09:08 AM

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 07/31/2008 at 08:35 AM

Application Version : 4.15.1000

Core Rules Database Version : 3522
Trace Rules Database Version: 1512

Scan type : Complete Scan
Total Scan Time : 00:12:55

Memory items scanned : 346
Memory threats detected : 1
Registry items scanned : 3934
Registry threats detected : 2
File items scanned : 13280
File threats detected : 13

Trojan.Unclassified/17PHolmes-A
C:\WINDOWS\17PHOLMES1001186.EXE
C:\WINDOWS\17PHOLMES1001186.EXE

Trojan.Downloader-Gen/MROFIN
[runner1] C:\WINDOWS\MROFINU1001186.EXE
C:\WINDOWS\MROFINU1001186.EXE
C:\WINDOWS\MROFINU1001186.EXE.TMP

Trojan.Downloader-Gen/RetAd
HKLM\Software\Microsoft\Windows\CurrentVersion\Run#runner1 [ C:\WINDOWS\mrofinu1001186.exe 61A847B5BBF72813329B39577AFF01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310 ]

Adware.ClickSpring
C:\WINDOWS\SYSTEM32\?YSTEM32\?SRSS.EXE

Trace.Known Threat Sources
C:\Documents and Settings\ThienTue\Local Settings\Temporary Internet Files\Content.IE5\0ILOO6IT\mrofinu[1].zip
C:\Documents and Settings\ThienTue\Local Settings\Temporary Internet Files\Content.IE5\8XEBK1YR\retadpu[1].htm
C:\Documents and Settings\ThienTue\Local Settings\Temporary Internet Files\Content.IE5\2FF60Y8K\retadpu[1].htm
C:\Documents and Settings\ThienTue\Local Settings\Temporary Internet Files\Content.IE5\8XEBK1YR\CAMN6JU7.htm
C:\Documents and Settings\ThienTue\Local Settings\Temporary Internet Files\Content.IE5\8XEBK1YR\17PHolmes[1].cmt
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\WH4PI1YZ\mrofinu[1].zip
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QZS72DSH\CANPCETX.htm
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\01CFYX4L\retadpu[1].htm
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\GHI5Q9MB\17PHolmes[1].cmt
SPYWARRRRRRRRRRRRRE!!!!

#13 Randomguy68

Randomguy68
  • Topic Starter

  • Members
  • 93 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:55 AM

Posted 31 July 2008 - 03:28 PM

Malwarebytes' Anti-Malware 1.23
Database version: 1008
Windows 5.1.2600 Service Pack 1

3:27:49 PM 7/31/2008
mbam-log-7-31-2008 (15-27-49).txt

Scan type: Quick Scan
Objects scanned: 38386
Time elapsed: 3 minute(s), 25 second(s)

Memory Processes Infected: 2
Memory Modules Infected: 1
Registry Keys Infected: 10
Registry Values Infected: 3
Registry Data Items Infected: 0
Folders Infected: 7
Files Infected: 17

Memory Processes Infected:
C:\Program Files\mjc\mjc.exe (Trojan.Agent) -> Unloaded process successfully.
C:\Program Files\Skra\Skra.exe (Trojan.Agent) -> Unloaded process successfully.

Memory Modules Infected:
C:\Program Files\Webtools\webtools.dll (Trojan.Agent) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\AppID\{ff46f4ab-a85f-487e-b399-3f191ac0fe23} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e4a04a1-a24d-45ae-aca4-949778400813} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{63334394-3da3-4b29-a041-03535909d361} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{15421b84-3488-49a7-ad18-cbf84a3efaf6} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{15421b84-3488-49a7-ad18-cbf84a3efaf6} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\testcpv6.bho (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\testcpv6.bho.1 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\testCPV6.DLL (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\WR (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo (Adware.PurityScan) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mjc (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mjc (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\skra (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\Outerinfo (Adware.Outerinfo) -> Quarantined and deleted successfully.
C:\Program Files\Outerinfo\FF (Adware.Outerinfo) -> Quarantined and deleted successfully.
C:\Program Files\Outerinfo\FF\components (Adware.Outerinfo) -> Quarantined and deleted successfully.
C:\Program Files\InetGet2 (Trojan.Downloader) -> Delete on reboot.
C:\Program Files\Webtools (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\mjc (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Skra (Trojan.Agent) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\Webtools\webtools.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\Components\srff.dll (Adware.SurfAccuracy) -> Quarantined and deleted successfully.
C:\Documents and Settings\ThienTue\Local Settings\Temporary Internet Files\Content.IE5\QPAP43CN\17PHolmes[1].cmt (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Program Files\Outerinfo\FF\chrome.manifest (Adware.Outerinfo) -> Quarantined and deleted successfully.
C:\Program Files\Outerinfo\FF\install.rdf (Adware.Outerinfo) -> Quarantined and deleted successfully.
C:\Program Files\Outerinfo\FF\components\FF.dll (Adware.Outerinfo) -> Quarantined and deleted successfully.
C:\Program Files\Outerinfo\FF\components\OuterinfoAds.xpt (Adware.Outerinfo) -> Quarantined and deleted successfully.
C:\Program Files\InetGet2\YazzleBundle-1560.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Program Files\mjc\mjc.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Skra\Skra.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\mrofinu1001186.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Common Files\Yazzle1560OinAdmin.exe (Adware.PurityScan) -> Quarantined and deleted successfully.
C:\Program Files\Common Files\Yazzle1560OinUninstaller.exe (Adware.PurityScan) -> Quarantined and deleted successfully.
C:\WINDOWS\b116.exe (Trojan.Downloader) -> Delete on reboot.
C:\WINDOWS\b155.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\b156.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\b157.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
SPYWARRRRRRRRRRRRRE!!!!

#14 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 72,912 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:08:55 AM

Posted 31 July 2008 - 03:53 PM

Ok this is a real stubborn piece.


Do this first. ( thx to Quietman7)
Go to Start > Settings > Control Panel, double-click on Add/Remove Programs. From within Add/Remove Programs highlight any of the following programs (if listed) and select "Remove".

ClickSpring
Cowabanga by OIN
ipwindows / ipwins
MediaTickets
MediaTickets by OIN
OIN
Outer Info Network
PurityScan
PurityScan by OIN
Snowball Wars by OIN
TizzleTalk
TizzleTalk by OIN
Yazzle by OIN
Yazzle ActiveX By OIN
Yazzle Cowabanga by OIN
Yazzle Kobe :filtered:! By OIN
Yazzle Picster by OIN
Yazzle Sudoku by OIN
Yazzle Snowballwars by OIN
Yazzle Kobe Balls! by OIN
Zolero Translator
or anything similar with OIN, Outer Info or Yazzle in them.
Important! Reboot when done.

Open My Computer or Windows Explorer, navigate to C:\Program Files and delete any of the named program folders listed above that you find (if they still exist).

If you do not see any icon for "OIN" or "(program) by OIN" in Add/Remove Programs, then download and run the Purity Scan uninstaller..
Save the Uninstaller to your desktop.
Double click on the OiUninstaller.exe icon on your desktop.
Click on "Run".
Enter the four digit code that is displayed and click on "Uninstall".
Click on "Ok" and reboot your computer.
Click here for Instructions with screenshots if needed.

Note: OiUninstaller uses UPX (ultimate packer for executables), an advanced file compressor and a method for compressing executable files to reduce their size to save space on a disk and download time. Some anti-virus programs such as Avast and Kaspersky may detect it as malware when attempting to download or unpack the compressed file.

Follow with:
Before we start fixing anything you should print out these instructions or copy them to a NotePad file so they will be accessible. Some steps will require you to disconnect from the Internet or use Safe Mode and you will not have access to this page.

Please download SDFix by AndyManchesta and save it to your desktop.
When using this tool, you must use the Administrator's account or an account with "Administrative rights"
  • Double click SDFix.exe and it will extract the files to %systemdrive%
  • (this is the drive that contains the Windows Directory, typically C:\SDFix).
  • DO NOT use it just yet.
Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Open the SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services or Registry Entries found then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts, the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
  • Copy and paste the contents of the results file Report.txt in your next reply.
-- If this error message is displayed when running SDFix: "The command prompt has been disabled by your administrator. Press any key to continue..."
Please go to Start Menu > Run > and copy/paste the following line:
%systemdrive%\SDFix\apps\swreg IMPORT %systemdrive%\SDFix\apps\Enable_Command_Prompt.reg
Press Ok and then run SDFix again.

-- If the Command Prompt window flashes on then off again on XP or Win 2000, please go to Start Menu > Run > and copy/paste the following line:
%systemdrive%\SDFix\apps\FixPath.exe /Q
Reboot and then run SDFix again.

-- If SDFix still does not run, check the %comspec% variable. Right-click My Computer > click Properties > Advanced > Environment Variables and check that the ComSpec variable points to cmd.exe.
%SystemRoot%\system32\cmd.exe

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#15 Randomguy68

Randomguy68
  • Topic Starter

  • Members
  • 93 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:55 AM

Posted 31 July 2008 - 04:58 PM

I ran the sdfix but an error about ntvdm keeps coming up, I also did the start run thing to stop the error but it didn't work? :thumbsup: You guys are so helpful though i have to thank you!! :flowers:
SPYWARRRRRRRRRRRRRE!!!!




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users