Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Monterrayf_unknown.exe, Drivera.dll And More Of Those Mainly Popups But My Computer Is Running So Slow...


  • Please log in to reply
1 reply to this topic

#1 r3d********

r3d********

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:06:49 AM

Posted 16 May 2007 - 05:37 PM

well i did the ad-aware and everything and on ad-aware this is the log it deleted everything it said except drivera.dll, driverb.dll and driverc.dll but my computer is running so slow it took me so long to do the scansif there is anything else u need tell me

ArchiveData(auto-quarantine- 2007-05-16 18-00-51.bckp)
Referencefile : SE1R170 14.05.2007
======================================================

WIN32.TROJAN.KOLWEB

obj[0]=Process : C:\WINDOWS\system32\driverb.dll
obj[1]=Process : C:\WINDOWS\system32\drivera.dll
obj[2]=Process : C:\WINDOWS\system32\driverc.dll
obj[3]=Regkey : clsid\{3b35d985-7648-4521-83be-1e16ae5cd05f}
obj[4]=Regkey : clsid\{54698a2f-2247-4538-82fc-2b5443d66945}
obj[5]=Regkey : clsid\{de0b3210-b828-475b-96f0-6796fe533e46}
obj[6]=Regkey : software\microsoft\windows\currentversion\explorer\browser helper objects\{3b35d985-7648-4521-83be-1e16ae5cd05f}
obj[7]=Regkey : software\microsoft\windows\currentversion\explorer\browser helper objects\{54698a2f-2247-4538-82fc-2b5443d66945}
obj[8]=Regkey : software\microsoft\windows\currentversion\explorer\browser helper objects\{de0b3210-b828-475b-96f0-6796fe533e46}
obj[71]=File : C:\Documents and Settings\Chris\Local Settings\Temp\monterreye_unknown.exe
obj[72]=File : C:\Documents and Settings\Lloyd\Local Settings\Temp\monterreyd_unknown.exe
obj[73]=File : C:\Documents and Settings\Lloyd\Local Settings\Temp\monterreye_unknown.exe
obj[74]=File : C:\Documents and Settings\Lloyd\Local Settings\Temp\~ds39990.tmp

WIN32.TROJANDOWNLOADER.ZLOB

obj[9]=Regkey : software\microsoft\windows\currentversion\explorer\browser helper objects\{67982bb7-0f95-44c5-92dc-e3af3dc19d6d}

TRACKING COOKIE

obj[10]=IECache Entry : Cookie:chris@serving-sys.com/
obj[11]=IECache Entry : Cookie:chris@apmebf.com/
obj[12]=IECache Entry : Cookie:chris@qksrv.net/
obj[13]=IECache Entry : Cookie:chris@tribalfusion.com/
obj[14]=IECache Entry : Cookie:chris@cs.sexcounter.com/
obj[15]=IECache Entry : Cookie:chris@zedo.com/
obj[16]=IECache Entry : Cookie:chris@tacoda.net/
obj[17]=IECache Entry : Cookie:chris@adtech.de/
obj[18]=IECache Entry : Cookie:chris@trafficmp.com/
obj[19]=IECache Entry : Cookie:chris@www.netster.com/
obj[20]=IECache Entry : Cookie:chris@sextracker.com/
obj[21]=IECache Entry : Cookie:chris@bravenet.com/
obj[22]=IECache Entry : Cookie:chris@live365.com/
obj[23]=IECache Entry : Cookie:chris@adbrite.com/stats/
obj[24]=IECache Entry : Cookie:chris@mediaplex.com/
obj[25]=IECache Entry : Cookie:chris@2o7.net/
obj[26]=IECache Entry : Cookie:chris@ads.pointroll.com/
obj[27]=IECache Entry : Cookie:chris@tremor.adbureau.net/
obj[28]=IECache Entry : Cookie:chris@realmedia.com/
obj[29]=IECache Entry : Cookie:chris@pro-market.net/
obj[30]=IECache Entry : Cookie:chris@insightexpressai.com/
obj[31]=IECache Entry : Cookie:chris@counter9.sextracker.com/
obj[32]=IECache Entry : Cookie:chris@ad.yieldmanager.com/
obj[33]=IECache Entry : Cookie:chris@casalemedia.com/
obj[34]=IECache Entry : Cookie:chris@fastclick.net/
obj[35]=IECache Entry : Cookie:chris@statse.webtrendslive.com/
obj[36]=IECache Entry : Cookie:chris@unicast.com/
obj[37]=IECache Entry : Cookie:chris@msnportal.112.2o7.net/
obj[38]=IECache Entry : Cookie:chris@bs.serving-sys.com/
obj[39]=IECache Entry : Cookie:chris@msnservices.112.2o7.net/
obj[40]=IECache Entry : Cookie:chris@media.adrevolver.com/adrevolver/
obj[41]=IECache Entry : Cookie:chris@netster.com/
obj[42]=IECache Entry : Cookie:chris@bluestreak.com/
obj[43]=IECache Entry : Cookie:chris@atdmt.com/
obj[44]=IECache Entry : Cookie:chris@findwhat.com/
obj[45]=IECache Entry : Cookie:chris@www.burstnet.com/
obj[46]=IECache Entry : Cookie:chris@tradedoubler.com/
obj[47]=IECache Entry : Cookie:chris@advertising.com/
obj[48]=IECache Entry : Cookie:chris@4.adbrite.com/
obj[49]=IECache Entry : Cookie:chris@doubleclick.net/
obj[50]=IECache Entry : Cookie:chris@statcounter.com/
obj[51]=IECache Entry : Cookie:chris@adopt.euroclick.com/
obj[52]=IECache Entry : Cookie:chris@counter12.sextracker.com/
obj[53]=IECache Entry : Cookie:chris@com.com/
obj[54]=IECache Entry : Cookie:chris@adbrite.com/
obj[55]=IECache Entry : Cookie:chris@revsci.net/
obj[56]=IECache Entry : Cookie:chris@digitalpoint.com/
obj[57]=IECache Entry : Cookie:chris@gatorarcade.aavalue.com/
obj[58]=IECache Entry : Cookie:chris@adrevolver.com/
obj[59]=IECache Entry : C:\Documents and Settings\Lloyd\Cookies\lloyd@ad.yieldmanager[1].txt
obj[60]=IECache Entry : C:\Documents and Settings\Lloyd\Cookies\lloyd@atdmt[2].txt
obj[61]=IECache Entry : C:\Documents and Settings\Lloyd\Cookies\lloyd@dealtime[1].txt
obj[62]=IECache Entry : C:\Documents and Settings\Lloyd\Cookies\lloyd@fastclick[1].txt
obj[63]=IECache Entry : C:\Documents and Settings\Lloyd\Cookies\lloyd@netster[1].txt
obj[64]=IECache Entry : C:\Documents and Settings\Lloyd\Cookies\lloyd@realmedia[2].txt
obj[65]=IECache Entry : C:\Documents and Settings\Lloyd\Cookies\lloyd@shopping.112.2o7[1].txt
obj[66]=IECache Entry : C:\Documents and Settings\Lloyd\Cookies\lloyd@stat.dealtime[2].txt
obj[67]=IECache Entry : C:\Documents and Settings\Lloyd\Cookies\lloyd@tacoda[1].txt
obj[68]=IECache Entry : C:\Documents and Settings\Lloyd\Cookies\lloyd@tribalfusion[2].txt
obj[69]=IECache Entry : C:\Documents and Settings\Lloyd\Cookies\lloyd@www.netster[1].txt
obj[70]=IECache Entry : C:\Documents and Settings\Lloyd\Cookies\lloyd@zedo[1].txt

HACKTOOL.KEYFINDER

obj[75]=File : C:\Documents and Settings\Lloyd\My Documents\keyfinder.exe
obj[76]=File : C:\Documents and Settings\Lloyd\My Documents\kf15b3.zip





Logfile of HijackThis v1.99.1
Scan saved at 6:16:47 PM, on 5/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54GSv2.exe
C:\WINDOWS\System32\LVComsX.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {566C2B45-015E-43BE-AF6D-30F204494EE7} - C:\WINDOWS\system32\driverc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {DE0B3210-B828-475B-96F0-6796FE533E46} - C:\WINDOWS\system32\driverf.dll
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\RunOnce: [AAW] "C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe" "+b1"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/...ZJzed004YYUS_ZJ
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://download.windowsupdate.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f...p1.0.0.15-3.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase8300.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1178321018364
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/...tiveXPlugin.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8D3F8690-1C3E-4182-A0A9-EA702BEB8E35}: NameServer = 208.34.3.3,208.34.3.2
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WUSB54GSv2SVC - Unknown owner - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe" "WUSB54GSv2.exe (file missing)

BC AdBot (Login to Remove)

 


#2 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:12:49 PM

Posted 17 May 2007 - 05:48 AM

Welcome to the BleepingComputer HijackThis Logs and Analysis forum r3d******** :thumbsup:

It appears you've no virus protection installed.
Download\install one of the following freeware options from the choice below.
Once installed update its definitions and then run a full system virus scan.

AVG7 Free Edition Antivirus:
http://free.grisoft.com/softw/70free/setup...ree_446a965.exe

Avast! 4 Home Edition:
http://files.avast.com/iavs4pro/setupeng.exe

Active Virus Shield
There's a nice setup tutorial Here:
http://www.activevirusshield.com/antivirus/freeav/

****************************

Please download Combofix and save to your desktop:
http://download.bleepingcomputer.com/sUBs/Beta/ComboFix.exe
Note:
It is important that it is saved directly to your desktop

Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
[/b]Post the C:\ComboFix.txt into your next reply.
Note:
Do not mouseclick combofix's window whilst it's running.
That may cause the program to freeze/hang.


Also post a new Hijackthis log please.
Posted Image
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users