Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Slow PC, malware found, ZeroAccess rootkit suspected


  • Please log in to reply
3 replies to this topic

#1 PrimeITS

PrimeITS

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:03:39 AM

Posted 06 February 2015 - 10:39 AM

Computer specs:

Windows 7 x64 with SP 1

2GB memory

Intel i3 processor

 

Initial symptoms:

Computer was slow, despite having cleared browser cache and unchecked any unnecessary startup processes or services via msconfig

 

Initial scanning:

Ran rkill, found zeroaccess rootkit reparse points

Ran malwarebytes, found several hundred detected objects, attempted remove, restarted computer

Ran malwarebytes, found most of the same infected objects as before, restarted computer

Ran spybot S&D and removed all found, restarted computer

Ran SuperAntiSpyware and removed all found, restarted computer

Ran rkill, still finding zeroaccess signs

Ran malwarebytes, still finding many detected objects

Ran a tool which shall not be named without staff approval

Ran rkill, still signs of zeroaccess

Ran malwarebytes "Custom Scan", selected only the rootkit option, still detected objects found, they all seem to reference MindSpark, C:\Qoobox\Quarantine and something about RadioRage_4j

 

I'll paste rkill and malwarebytes logs below.  I'll be greatly appreciative of any help that could be given!

 

Kind regards,

Mike

 

Rkill 2.6.5 by Lawrence Abrams (Grinler)
Copyright 2008-2015 BleepingComputer.com
More Information about Rkill can be found at this link:
 
Program started at: 02/06/2015 09:08:03 AM in x64 mode.
Windows Version: Windows 7 Professional Service Pack 1
 
Checking for Windows services to stop:
 
 * No malware services found to stop.
 
Checking for processes to terminate:
 
 * No malware processes found to kill.
 
Checking Registry for malware related settings:
 
 * No issues found in the Registry.
 
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
 
Performing miscellaneous checks:
 
 * ALERT: ZEROACCESS Reparse Point/Junction found!
 
     * C:\Windows\winsxs\amd64_security-malware-windows-defender-events_31bf3856ad364e35_6.1.7600.16385_none_118cf1dcd54a3dea\MpEvMsg.dll => c:\windows\system32\config [File]
     * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306\MpAsDesc.dll => c:\windows\system32\config [File]
     * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306\MpClient.dll => c:\windows\system32\config [File]
     * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306\MpCmdRun.exe => c:\windows\system32\config [File]
     * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306\MpCommu.dll => c:\windows\system32\config [File]
     * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306\MpOAV.dll => c:\windows\system32\config [File]
     * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306\MpRTP.dll => c:\windows\system32\config [File]
     * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306\MpSvc.dll => c:\windows\system32\config [File]
     * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306\MSASCui.exe => c:\windows\system32\config [File]
     * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306\MsMpCom.dll => c:\windows\system32\config [File]
     * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306\MsMpLics.dll => c:\windows\system32\config [File]
     * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306\MsMpRes.dll => c:\windows\system32\config [File]
 
 * No issues found.
 
Checking Windows Service Integrity: 
 
 * WinDefend (WinDefend) is not Running.
   Startup Type set to: Automatic
 
Searching for Missing Digital Signatures: 
 
 * No issues found.
 
Checking HOSTS File: 
 
 * HOSTS file entries found: 
 
  127.0.0.1       localhost
 
Program finished at: 02/06/2015 09:08:10 AM
Execution time: 0 hours(s), 0 minute(s), and 7 seconds(s)
 
======================================================================
 
Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 2/5/2015
Scan Time: 12:02:42 PM
Logfile: 
Administrator: Yes
 
Version: 2.00.4.1028
Malware Database: v2015.02.05.08
Rootkit Database: v2015.02.03.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
 
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: PrimeAdmin
 
Scan Type: Threat Scan
Result: Cancelled
Objects Scanned: 50533
Time Elapsed: 3 min, 52 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
Processes: 2
PUP.Optional.MindSpark, C:\Program Files (x86)\RadioRage_4j\bar\1.bin\APPINTEGRATOR.EXE, 4724, No Action By User, [4c90ef2b4a40e84e64a12aa07b8652ae]
PUP.Optional.MindSpark, C:\Program Files (x86)\RadioRage_4j\bar\1.bin\AppIntegrator64.exe, 4852, No Action By User, [9d3fa6744b3f6fc747be6268ec15dc24]
 
Modules: 7
PUP.Optional.MindSpark, C:\Program Files (x86)\RadioRage_4j\bar\1.bin\APPINTEGRATORSTUB.DLL, No Action By User, [18c49f7b91f9a096ca3bd5f51ae753ad], 
PUP.Optional.MindSpark, C:\Program Files (x86)\RadioRage_4j\bar\1.bin\APPINTEGRATORSTUB.DLL, No Action By User, [18c49f7b91f9a096ca3bd5f51ae753ad], 
PUP.Optional.MindSpark, C:\Program Files (x86)\RadioRage_4j\bar\1.bin\APPINTEGRATORSTUB.DLL, No Action By User, [18c49f7b91f9a096ca3bd5f51ae753ad], 
PUP.Optional.MindSpark, C:\Program Files (x86)\RadioRage_4j\bar\1.bin\HPG.DLL, No Action By User, [5a8262b8b7d33ff7788d26a4de23a45c], 
PUP.Optional.MindSpark, C:\Program Files (x86)\RadioRage_4j\bar\1.bin\4jdlghk.dll, No Action By User, [e4f8b96190fa280e996c309ad72a04fc], 
PUP.Optional.MindSpark, C:\Program Files (x86)\RadioRage_4j\bar\1.bin\4jSrcAs.dll, No Action By User, [f1eb180262289d991fe68f3b9f620000], 
PUP.Optional.MindSpark, C:\Program Files (x86)\RadioRage_4j\bar\1.bin\TOOLBARGUARD.DLL, No Action By User, [687454c614769d9975909634a958c13f], 
 
Registry Keys: 52
PUP.Optional.MindSpark, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RadioRage_4jService, No Action By User, [a7356cae3e4c3bfb6e97a525a75a59a7], 
PUP.Optional.MindSpark, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{6562e272-88e1-4dff-8ff8-fe1a05323d36}, No Action By User, [e4f8b96190fa280e996c309ad72a04fc], 
PUP.Optional.MindSpark, HKLM\SOFTWARE\CLASSES\TYPELIB\{d0e90465-cf35-480d-b520-e1e3bde802f5}, No Action By User, [e4f8b96190fa280e996c309ad72a04fc], 
PUP.Optional.MindSpark, HKLM\SOFTWARE\CLASSES\INTERFACE\{6D32BB6F-7969-48BF-836A-C14CDFC72D72}, No Action By User, [e4f8b96190fa280e996c309ad72a04fc], 
PUP.Optional.MindSpark, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{6D32BB6F-7969-48BF-836A-C14CDFC72D72}, No Action By User, [e4f8b96190fa280e996c309ad72a04fc], 
PUP.Optional.MindSpark, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{d0e90465-cf35-480d-b520-e1e3bde802f5}, No Action By User, [e4f8b96190fa280e996c309ad72a04fc], 
PUP.Optional.MindSpark, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5848763c-2668-44ca-adbe-2999a6ee2858}, No Action By User, [f1eb180262289d991fe68f3b9f620000], 
PUP.Optional.MindSpark, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{5848763C-2668-44CA-ADBE-2999A6EE2858}, No Action By User, [f1eb180262289d991fe68f3b9f620000], 
PUP.Optional.MindSpark, HKU\S-1-5-21-1997233458-2529485358-4280198481-1173-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{5848763C-2668-44CA-ADBE-2999A6EE2858}, No Action By User, [f1eb180262289d991fe68f3b9f620000], 
PUP.Optional.MindSpark, HKU\S-1-5-21-580102069-1786471665-2579867939-1156-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{5848763C-2668-44CA-ADBE-2999A6EE2858}, No Action By User, [f1eb180262289d991fe68f3b9f620000], 
PUP.Optional.MindSpark, HKU\S-1-5-21-580102069-1786471665-2579867939-1220-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{5848763C-2668-44CA-ADBE-2999A6EE2858}, No Action By User, [f1eb180262289d991fe68f3b9f620000], 
PUP.Optional.MindSpark, HKU\S-1-5-21-1997233458-2529485358-4280198481-1173-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{5848763C-2668-44CA-ADBE-2999A6EE2858}, No Action By User, [f1eb180262289d991fe68f3b9f620000], 
PUP.Optional.MindSpark, HKU\S-1-5-21-580102069-1786471665-2579867939-1156-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{5848763C-2668-44CA-ADBE-2999A6EE2858}, No Action By User, [f1eb180262289d991fe68f3b9f620000], 
PUP.Optional.MindSpark, HKU\S-1-5-21-580102069-1786471665-2579867939-1220-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{5848763C-2668-44CA-ADBE-2999A6EE2858}, No Action By User, [f1eb180262289d991fe68f3b9f620000], 
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{48909954-14fb-4971-a7b3-47e7af10b38a}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{78ba36c9-6036-482b-b48d-ecca6f964b84}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1997233458-2529485358-4280198481-1173-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{78BA36C9-6036-482B-B48D-ECCA6F964B84}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKU\S-1-5-21-580102069-1786471665-2579867939-1156-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{78BA36C9-6036-482B-B48D-ECCA6F964B84}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKU\S-1-5-21-580102069-1786471665-2579867939-1220-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{78BA36C9-6036-482B-B48D-ECCA6F964B84}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1997233458-2529485358-4280198481-1173-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{78BA36C9-6036-482B-B48D-ECCA6F964B84}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKU\S-1-5-21-580102069-1786471665-2579867939-1156-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{78BA36C9-6036-482B-B48D-ECCA6F964B84}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKU\S-1-5-21-580102069-1786471665-2579867939-1220-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{78BA36C9-6036-482B-B48D-ECCA6F964B84}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{9638b7d6-11f5-4406-b387-327642a11ffb}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{b872d222-3f52-4cd9-a4be-9d69ee4f293d}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{37B204F8-CD97-409B-BDBF-41C0EC0DFF24}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{7AFA5495-6C01-4BB8-AE21-C3BD6AB2F17C}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A1448C6E-0452-4550-B852-A1CE666D4907}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A25AA6E2-1CDE-4D0F-A5D4-4898D7FB3C86}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A5C9CB1C-1C0A-45A2-81CC-1DD342D0A478}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{F2B8FCF4-73EA-4D12-AAFE-72909AFBA0A4}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{37B204F8-CD97-409B-BDBF-41C0EC0DFF24}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{7AFA5495-6C01-4BB8-AE21-C3BD6AB2F17C}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A1448C6E-0452-4550-B852-A1CE666D4907}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A25AA6E2-1CDE-4D0F-A5D4-4898D7FB3C86}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A5C9CB1C-1C0A-45A2-81CC-1DD342D0A478}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F2B8FCF4-73EA-4D12-AAFE-72909AFBA0A4}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{b872d222-3f52-4cd9-a4be-9d69ee4f293d}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\RadioRage_4j.SettingsPlugin.1, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\RadioRage_4j.SettingsPlugin, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\RadioRage_4j.SettingsPlugin, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\RadioRage_4j.SettingsPlugin.1, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKU\S-1-5-21-580102069-1786471665-2579867939-1220-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{9638B7D6-11F5-4406-B387-327642A11FFB}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{9638B7D6-11F5-4406-B387-327642A11FFB}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\RadioRage_4jbar Uninstall Firefox, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\RadioRage_4jbar Uninstall Internet Explorer, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{48909954-14FB-4971-A7B3-47E7AF10B38A}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1997233458-2529485358-4280198481-1173-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{48909954-14FB-4971-A7B3-47E7AF10B38A}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKU\S-1-5-21-580102069-1786471665-2579867939-1156-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{48909954-14FB-4971-A7B3-47E7AF10B38A}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKU\S-1-5-21-580102069-1786471665-2579867939-1220-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{48909954-14FB-4971-A7B3-47E7AF10B38A}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1997233458-2529485358-4280198481-1173-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{48909954-14FB-4971-A7B3-47E7AF10B38A}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKU\S-1-5-21-580102069-1786471665-2579867939-1156-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{48909954-14FB-4971-A7B3-47E7AF10B38A}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKU\S-1-5-21-580102069-1786471665-2579867939-1220-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{48909954-14FB-4971-A7B3-47E7AF10B38A}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
 
Registry Values: 17
PUP.Optional.MindSpark, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|RadioRage AppIntegrator 32-bit, C:\PROGRA~2\RADIOR~2\bar\1.bin\AppIntegrator.exe, No Action By User, [4c90ef2b4a40e84e64a12aa07b8652ae]
PUP.Optional.MindSpark, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|RadioRage AppIntegrator 64-bit, C:\PROGRA~2\RADIOR~2\bar\1.bin\AppIntegrator64.exe, No Action By User, [9d3fa6744b3f6fc747be6268ec15dc24]
IPH.Trojan.Clicker.W7, HKU\S-1-5-21-580102069-1786471665-2579867939-1220-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|ynckapqnav, regsvr32.exe /s "C:\Users\MPope\AppData\Local\{18CDF210-D32E-44A3-8B76-DC776B77669E}\ynckapqnav.dll", No Action By User, [8e4e72a8612979bdfedd44bc09f75ca4]
PUP.Optional.MindSpark, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|RadioRage EPM Support, "C:\PROGRA~2\RADIOR~2\bar\1.bin\4jmedint.exe" T8EPMSUP.DLL,S, No Action By User, [3f9d8595e1a9c1758481dbef12ef847c]
PUP.Optional.MindSpark, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|RadioRage Search Scope Monitor, "C:\PROGRA~2\RADIOR~2\bar\1.bin\4jsrchmn.exe" /m=2 /w /h, No Action By User, [e5f7948694f60531bf468842936efc04]
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1997233458-2529485358-4280198481-1173-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{78BA36C9-6036-482B-B48D-ECCA6F964B84}, Ã6ºx6`+H´ÂìÃoâKâ, No Action By User, [e2fa79a16e1c04328da419e860a3e41c]
PUP.Optional.MindSpark.A, HKU\S-1-5-21-580102069-1786471665-2579867939-1156-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{78BA36C9-6036-482B-B48D-ECCA6F964B84}, Ã6ºx6`+H´ÂìÃoâKâ, No Action By User, [e2fa79a16e1c04328da419e860a3e41c]
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{78BA36C9-6036-482B-B48D-ECCA6F964B84}, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1997233458-2529485358-4280198481-1173-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER\{78BA36C9-6036-482B-B48D-ECCA6F964B84}, No Action By User, [e6f6d04a6921ed49ca69966bbc47c838], 
PUP.Optional.MindSpark.A, HKU\S-1-5-21-580102069-1786471665-2579867939-1156-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER\{78BA36C9-6036-482B-B48D-ECCA6F964B84}, No Action By User, [21bbb06a3951270f151e60a10bf8d62a], 
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1997233458-2529485358-4280198481-1173-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS\{3c35ad63-af1d-4e21-b484-b6651a8efcf9}, No Action By User, [08d4001a137742f45b97728da062758b], 
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1997233458-2529485358-4280198481-1173-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{3C35AD63-AF1D-4E21-B484-B6651A8EFCF9}, No Action By User, [08d4001a137742f45b97728da062758b], 
PUP.Optional.MindSpark.A, HKU\S-1-5-21-580102069-1786471665-2579867939-1156-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{3C35AD63-AF1D-4E21-B484-B6651A8EFCF9}, No Action By User, [08d4001a137742f45b97728da062758b], 
PUP.Optional.MindSpark.A, HKU\S-1-5-21-580102069-1786471665-2579867939-1220-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{3C35AD63-AF1D-4E21-B484-B6651A8EFCF9}, No Action By User, [08d4001a137742f45b97728da062758b], 
PUP.Optional.MindSpark.A, HKU\S-1-5-21-580102069-1786471665-2579867939-1156-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS\{3c35ad63-af1d-4e21-b484-b6651a8efcf9}, No Action By User, [7d5f36e4fc8e26104aa89b64a062b749], 
PUP.Optional.MindSpark.A, HKU\S-1-5-21-580102069-1786471665-2579867939-1220-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS\{3c35ad63-af1d-4e21-b484-b6651a8efcf9}, No Action By User, [796399812466082e1cd6ec1330d240c0], 
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{78ba36c9-6036-482b-b48d-ecca6f964b84}, No Action By User, [fede3ae07d0d5ed8062d956c36cd857b], 
 
Registry Data: 0
(No malicious items detected)
 
Folders: 0
(No malicious items detected)
 
Files: 12
PUP.Optional.MindSpark, C:\Program Files (x86)\RadioRage_4j\bar\1.bin\APPINTEGRATORSTUB.DLL, No Action By User, [18c49f7b91f9a096ca3bd5f51ae753ad], 
PUP.Optional.MindSpark, C:\Program Files (x86)\RadioRage_4j\bar\1.bin\4jbarsvc.exe, No Action By User, [a7356cae3e4c3bfb6e97a525a75a59a7], 
PUP.Optional.MindSpark, C:\Program Files (x86)\RadioRage_4j\bar\1.bin\APPINTEGRATOR.EXE, No Action By User, [4c90ef2b4a40e84e64a12aa07b8652ae], 
PUP.Optional.MindSpark, C:\Program Files (x86)\RadioRage_4j\bar\1.bin\HPG.DLL, No Action By User, [5a8262b8b7d33ff7788d26a4de23a45c], 
PUP.Optional.MindSpark, C:\Program Files (x86)\RadioRage_4j\bar\1.bin\4jdlghk.dll, No Action By User, [e4f8b96190fa280e996c309ad72a04fc], 
PUP.Optional.MindSpark, C:\Program Files (x86)\RadioRage_4j\bar\1.bin\4jSrcAs.dll, No Action By User, [f1eb180262289d991fe68f3b9f620000], 
PUP.Optional.MindSpark, C:\Program Files (x86)\RadioRage_4j\bar\1.bin\TOOLBARGUARD.DLL, No Action By User, [687454c614769d9975909634a958c13f], 
PUP.Optional.MindSpark, C:\Program Files (x86)\RadioRage_4j\bar\1.bin\AppIntegrator64.exe, No Action By User, [9d3fa6744b3f6fc747be6268ec15dc24], 
IPH.Trojan.Clicker.W7, C:\Users\MPope\AppData\Local\{18CDF210-D32E-44A3-8B76-DC776B77669E}\ynckapqnav.dll, No Action By User, [8e4e72a8612979bdfedd44bc09f75ca4], 
PUP.Optional.MindSpark, C:\Program Files (x86)\RadioRage_4j\bar\1.bin\4jmedint.exe, No Action By User, [3f9d8595e1a9c1758481dbef12ef847c], 
PUP.Optional.MindSpark, C:\Program Files (x86)\RadioRage_4j\bar\1.bin\4jSrchMn.exe, No Action By User, [e5f7948694f60531bf468842936efc04], 
PUP.Optional.MindSpark.A, C:\Program Files (x86)\RadioRage_4j\bar\1.bin\4jbar.dll, No Action By User, [e2fa79a16e1c04328da419e860a3e41c], 
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)

 

 



BC AdBot (Login to Remove)

 


m

#2 hayyagahoy

hayyagahoy

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:04:39 AM

Posted 06 February 2015 - 10:47 AM

I have used this "use at your own risk" tool before when I had the zeroaccess rootkit : http://kb.eset.com/esetkb/index?page=content&id=SOLN2895

 

It seemed to find and clean it up for me even when malwarebytes wouldn't.



#3 PrimeITS

PrimeITS
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:03:39 AM

Posted 06 February 2015 - 12:10 PM

I have used this "use at your own risk" tool before when I had the zeroaccess rootkit : http://kb.eset.com/esetkb/index?page=content&id=SOLN2895

 

It seemed to find and clean it up for me even when malwarebytes wouldn't.

 

Thanks for your suggestion.  I downloaded the tool and ran it, and it tells me right off the bat "You don't have Win64/Sirefef in your system."



#4 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 50,582 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:04:39 AM

Posted 06 February 2015 - 04:52 PM

...I downloaded the tool and ran it, and it tells me right off the bat "You don't have Win64/Sirefef in your system."

RKill says....

* ALERT: ZEROACCESS Reparse Point/Junction found!

Disinfection will probably require the use of more powerful tools than we can recommend in this forum. Before that can be done you will need to create and post a FRST log for further investigation.

Please follow the instructions in the Malware Removal and Log Section Preparation Guide starting at Step 6.
  • If you cannot complete a step, then skip it and continue with the next.
  • In Step 6 there are instructions for downloading and running FRST which will create two logs.
When you have done that, post your logs in the Virus, Trojan, Spyware, and Malware Removal Logs forum, NOT here, for assistance by the Malware Response Team.

Start a new topic, give it a relevant title and post your log(s) along with a brief description of your problem, a summary of any anti-malware tools you have used and a summary of any steps that you have performed on your own. If you cannot produce any of the required logs...start the new topic anyway. Explain that you followed the Prep. Guide, were unable to create the logs, and describe what happened when you tried to create them. A member of the Malware Removal Team will walk you through, step by step, on how to clean your computer.

After doing this, please reply back in this thread with a link to the new topic so we can close this one.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users