Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

ACDSeeQV.exe


  • This topic is locked This topic is locked
9 replies to this topic

#1 DonCorneo

DonCorneo

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ
  • Local time:07:04 AM

Posted 18 April 2010 - 08:19 PM

As an on going check to make sure my PC is clean, I tried a-squared free. I have used Norton online, McAfee online, ZoneAlarm Anti-virus (installed), a couple of other online anti-virus and bunch of anti-malware/spyware programs.
None of the other anti-virus/malware have reported this, nor the Motorola entries, before And I am wondering if this is a FP or not. a-squared is reporting them as High Risk. I know the Combofix can be a FP.
As can be seen, the files are in their appropriate directories. a-squared scan has finished, but I have not selected what action to take yet.
I did get a submission request, but the acdseeqv.exe file was not a part of the listed ones to be submitted.

What do you know about this being a Trojan or not?

Windows 7 64 bit

avast! online scanner reports all but Combofix as "Clear"

As per advice from keyboardNinja, I have Quarantined the files.
Since I am using W7 64, I am uninstalling Combofix to remove that file.



a-squared log:

a-squared Free - Version 4.5
Last update: 4/17/2010 7:37:27 PM

Scan settings:

Scan type: Deep Scan
Objects: Memory, Traces, Cookies, C:\, D:\, E:\
Scan archives: On
Heuristics: Off
ADS Scan: On

Scan start: 4/17/2010 7:37:50 PM

D:\ProgInstalls\Combofix\DHL_Label_9274.zip/DHL_Label_9274.exe detected: Trojan.Win32.Bredolab!IK
D:\Program Files\ACD Systems\ACDSee\9.0\ACDSeeQV.exe detected: Trojan-Downloader.Win32.Agent.dhct!A2
D:\Program Files\Motorola\Media Downloader\lang_ara.dll detected: Trojan.Crypt!IK
D:\Program Files\Motorola\Media Downloader\lang_eng.dll detected: Trojan.Crypt!IK
D:\Program Files\Motorola\Media Downloader\lang_heb.dll detected: Trojan.Crypt!IK
D:\Program Files\Motorola\Media Downloader\lang_kor.dll detected: Trojan.Crypt!IK
D:\Program Files\Motorola\Media Downloader\lang_por.dll detected: Trojan.Crypt!IK

Scanned

Files: 1366166
Traces: 574680
Cookies: 101
Processes: 74

Found

Files: 7
Traces: 0
Cookies: 0
Processes: 0
Registry keys: 0

Scan end: 4/18/2010 1:46:11 AM
Scan time: 6:08:21

Edited by DonCorneo, 18 April 2010 - 10:59 PM.


BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,490 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:07:04 AM

Posted 18 April 2010 - 11:03 PM

Hello interesting that ComboFix ran on a 64 bit system as it's not designed to. I am moving this to the AM I infected forum as there is no DDS log which is required here.


Please go here....
Preparation Guide ,do steps 6 - 9.

Create a DDS log and post it in the new topic explained in step 9,which is here Virus, Trojan, Spyware, and Malware Removal Logs and not in this topic,thanks.
If Gmer won't run,skip it and move on.
Let me know if that went well.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 DonCorneo

DonCorneo
  • Topic Starter

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ
  • Local time:07:04 AM

Posted 18 April 2010 - 11:14 PM

Combofix did not fully run, I get the incompatible OS error after it tries to load.

#4 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,490 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:07:04 AM

Posted 18 April 2010 - 11:18 PM

Ok, I didn't yhink it could.... Do the prep Guide.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#5 DonCorneo

DonCorneo
  • Topic Starter

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ
  • Local time:07:04 AM

Posted 18 April 2010 - 11:29 PM

Doing it now, but Gmer started with error: "C:\Windows\system32\config\system: The system cannot find the file specified."
Another error poped up but disappeared to quick for me to read anything.

The tick boxes for System, Sections, IAT/EAT, Devices, Modules, Processes, Threads, Libraries, and Show all are grayed out, but unchecked.

It is scanning right now though.

DDS worked and saved files.

#6 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,490 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:07:04 AM

Posted 18 April 2010 - 11:37 PM

If GMER won't complete post the DDS only then.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#7 DonCorneo

DonCorneo
  • Topic Starter

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ
  • Local time:07:04 AM

Posted 18 April 2010 - 11:48 PM

Gmer completed, but only one thing showed, but all the saved file has is:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-19 00:31:20
Windows 6.1.7600
Running: gmer.exe


---- Files - GMER 1.0.15 ----

File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS04333.log 1048576 bytes

---- EOF - GMER 1.0.15 ----

#8 DonCorneo

DonCorneo
  • Topic Starter

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ
  • Local time:07:04 AM

Posted 18 April 2010 - 11:57 PM

New post made as per instructions.

#9 DonCorneo

DonCorneo
  • Topic Starter

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ
  • Local time:07:04 AM

Posted 19 April 2010 - 02:26 AM

Will be back around 8pm est 04/19/10

#10 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,490 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:07:04 AM

Posted 19 April 2010 - 10:16 AM

Ok, looks good now.
Now that your log is properly posted, you should NOT make further changes to your computer (install/uninstall programs, use special fix tools, delete files, edit the registry, etc) unless advised by a Malware Removal Team member, nor should you continue to ask for help elsewhere. Doing so can result in system changes which may not show it the log you already posted. Further, any modifications you make on your own may cause confusion for the helper assisting you and could complicate the malware removal process which would extend the time it takes to clean your computer.

From this point on the Malware Removal Team should be the only members that you take advice from, until they have verified your log as clean.

Please be patient. It may take a while to get a response because the Malware Removal Team members are very busy working logs posted before yours. They are volunteers who will help you out as soon as possible. Once you have made your post and are waiting, please DO NOT make another reply until it has been responded to by a member of the Malware Removal Team. Generally the staff checks the forum for postings that have 0 replies as this makes it easier for them to identify those who have not been helped. If you post another response there will be 1 reply. A team member, looking for a new log to work may assume another HJT Team member is already assisting you and not open the thread to respond.

To avoid confusion, I am closing this topic.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users