Jump to content

Trojan Dropper BCMiner


Recommended Posts

Hooray! :D We're nearly there!

Please do the following:

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

KILLALL::

FCopy::

c:\windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe | c:\windows\system32\services.exe

Reboot::

Save this as CFScript.txt, in the same location as ComboFix.exe

CFScriptB-4.gif

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I shall require in your next reply.

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

Please include the newly-created C:\ComboFix.txt in your next reply, and let me know how things are running now ;)

Link to post
Share on other sites

ComboFix 12-06-03.05 - Sami 06/03/2012 21:13:50.2.2 - x64

Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.2811.1378 [GMT -7:00]

Running from: c:\users\Sami\Desktop\ComboFix.exe

Command switches used :: c:\users\Sami\Desktop\CFScript.txt

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

.

--------------- FCopy ---------------

.

c:\windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe --> c:\windows\system32\services.exe

.

((((((((((((((((((((((((( Files Created from 2012-05-04 to 2012-06-04 )))))))))))))))))))))))))))))))

.

.

2012-06-04 04:25 . 2012-06-04 04:25 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-06-04 04:25 . 2012-06-04 04:25 -------- d-----w- c:\users\Administrator\AppData\Local\temp

2012-06-02 04:36 . 2012-06-02 04:36 -------- d-----w- c:\users\Sami\AppData\Roaming\World-LooM

2012-06-02 04:11 . 2012-06-02 04:12 -------- d-----w- C:\FRST

2012-06-01 17:09 . 2012-06-01 17:12 -------- d-----w- c:\users\Sami\AppData\Roaming\ImgBurn

2012-06-01 17:02 . 2012-06-01 17:02 -------- d-----w- c:\program files (x86)\ImgBurn

2012-06-01 16:52 . 2012-06-01 16:52 -------- d-----w- c:\program files (x86)\Free Offers from Freeze.com

2012-06-01 10:20 . 2012-06-01 10:22 -------- d---a-w- C:\Kaspersky Rescue Disk 10.0

2012-06-01 04:20 . 2012-06-01 04:20 -------- d-----w- c:\program files (x86)\Kingdom Chronicles - Collector's Edition

2012-05-29 18:19 . 2012-05-29 18:19 16200 ----a-w- c:\windows\stinger.sys

2012-05-29 18:18 . 2012-05-30 05:34 -------- d-----w- c:\program files (x86)\stinger

2012-05-29 03:31 . 2012-05-29 03:31 -------- d-----w- c:\users\Sami\AppData\Roaming\Orneon

2012-05-28 21:38 . 2012-05-28 21:38 -------- d-----w- c:\windows\system32\SPReview

2012-05-28 05:34 . 2012-05-28 05:34 -------- d-sh--w- c:\windows\SysWow64\%APPDATA%

2012-05-28 05:27 . 2012-05-28 05:27 -------- d-----w- c:\users\Sami\AppData\Roaming\Dark Dimensions - Wax Beauty Strategy Guide

2012-05-28 05:22 . 2012-05-28 05:22 -------- d-----w- c:\users\Sami\AppData\Roaming\Eipix

2012-05-27 23:34 . 2012-05-08 17:02 8955792 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{DA148176-3F26-4739-9F0D-BD3B9430579F}\mpengine.dll

2012-05-26 19:33 . 2012-05-28 21:44 -------- d-----w- c:\users\Sami\AppData\Roaming\Octoshape

2012-05-26 18:09 . 2012-05-08 17:02 8955792 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll

2012-05-24 04:08 . 2012-05-24 04:08 -------- d-----w- c:\users\Sami\AppData\Roaming\Friday's games

2012-05-24 04:03 . 2012-05-29 03:30 -------- d-----w- c:\program files (x86)\Tiger Games

2012-05-23 01:12 . 2012-05-23 01:12 -------- d-----w- c:\windows\SysWow64\2080

2012-05-22 03:47 . 2012-05-22 03:47 -------- d-----w- c:\users\Sami\AppData\Roaming\SkyGoblin

2012-05-22 03:43 . 2012-05-22 03:43 466456 ----a-w- c:\windows\system32\wrap_oal.dll

2012-05-22 03:43 . 2012-05-22 03:43 444952 ----a-w- c:\windows\SysWow64\wrap_oal.dll

2012-05-22 03:43 . 2012-05-22 03:43 122904 ----a-w- c:\windows\system32\OpenAL32.dll

2012-05-22 03:43 . 2012-05-22 03:43 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll

2012-05-22 03:43 . 2012-05-22 03:43 -------- d-----w- c:\program files (x86)\OpenAL

2012-05-22 03:41 . 2012-05-22 03:41 -------- d-----w- c:\programdata\JustAdventure

2012-05-22 03:26 . 2012-05-22 03:26 -------- d-----w- c:\program files (x86)\directx

2012-05-16 01:12 . 2012-05-23 01:12 -------- d-----w- c:\windows\SysWow64\1080

2012-05-15 05:37 . 2012-05-15 05:37 -------- d-----w- c:\program files (x86)\Common Files\Skype

2012-05-15 05:37 . 2012-05-15 05:38 -------- d-----w- c:\program files (x86)\Common Files\Overwolf

2012-05-15 05:37 . 2012-05-15 05:38 -------- d-----w- c:\program files (x86)\Overwolf

2012-05-15 05:36 . 2012-06-04 02:56 -------- d-----w- c:\users\Sami\AppData\Local\Overwolf

2012-05-15 03:11 . 2012-05-15 03:11 -------- d-----w- c:\users\Sami\AppData\Roaming\FOG Downloader

2012-05-11 23:46 . 2012-03-03 06:29 1541120 ----a-w- c:\windows\system32\DWrite.dll

2012-05-11 23:46 . 2012-03-03 06:29 320512 ----a-w- c:\windows\system32\d3d10_1core.dll

2012-05-11 23:46 . 2012-03-03 06:29 1837568 ----a-w- c:\windows\system32\d3d10warp.dll

2012-05-11 23:46 . 2012-03-03 05:40 1074176 ----a-w- c:\windows\SysWow64\DWrite.dll

2012-05-11 23:46 . 2012-03-03 05:40 1170944 ----a-w- c:\windows\SysWow64\d3d10warp.dll

2012-05-11 23:46 . 2012-03-03 05:40 218624 ----a-w- c:\windows\SysWow64\d3d10_1core.dll

2012-05-11 23:46 . 2012-03-03 06:29 197120 ----a-w- c:\windows\system32\d3d10_1.dll

2012-05-11 23:46 . 2012-03-03 06:29 902656 ----a-w- c:\windows\system32\d2d1.dll

2012-05-11 23:46 . 2012-03-03 05:40 739840 ----a-w- c:\windows\SysWow64\d2d1.dll

2012-05-11 23:46 . 2012-03-03 05:40 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll

2012-05-11 23:45 . 2012-03-17 07:55 75632 ----a-w- c:\windows\system32\drivers\partmgr.sys

2012-05-11 23:45 . 2012-04-02 05:34 5504880 ----a-w- c:\windows\system32\ntoskrnl.exe

2012-05-11 23:45 . 2012-04-02 03:01 3143680 ----a-w- c:\windows\system32\win32k.sys

2012-05-11 23:45 . 2012-04-02 04:46 3958128 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe

2012-05-11 23:45 . 2012-04-02 04:46 3902320 ----a-w- c:\windows\SysWow64\ntoskrnl.exe

2012-05-11 23:45 . 2012-03-30 11:09 1895280 ----a-w- c:\windows\system32\drivers\tcpip.sys

2012-05-11 23:45 . 2012-04-02 05:24 1367552 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll

2012-05-11 23:45 . 2012-04-02 04:40 936960 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll

2012-05-10 02:47 . 2012-05-10 02:47 768848 ----a-w- c:\windows\SysWow64\msvcr100.dll

2012-05-10 02:47 . 2012-05-10 02:47 421200 ----a-w- c:\windows\SysWow64\msvcp100.dll

2012-05-09 01:12 . 2012-05-16 01:12 -------- d-----w- c:\windows\SysWow64\3013

2012-05-06 04:18 . 2012-05-06 04:18 -------- d-----w- c:\users\Sami\AppData\Roaming\LegacyGames

2012-05-05 15:49 . 2012-05-05 15:49 -------- d-----w- c:\users\Sami\AppData\Roaming\Black Sea Studios

2012-05-05 14:10 . 2012-05-20 15:39 -------- d-----w- c:\program files (x86)\Common Files\Steam

2012-05-05 14:10 . 2012-06-04 04:27 -------- d-----w- c:\program files (x86)\Steam

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-04-04 22:56 . 2011-11-01 01:38 24904 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-03-21 03:44 . 2011-04-27 22:25 98688 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys

2012-03-21 03:44 . 2011-04-18 20:18 203888 ----a-w- c:\windows\system32\drivers\MpFilter.sys

2012-03-07 05:39 . 2010-07-11 05:29 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll

.

.

((((((((((((((((((((((((((((( SnapShot@2012-06-04_02.53.47 )))))))))))))))))))))))))))))))))))))))))

.

+ 2010-07-11 03:12 . 2012-06-04 04:28 49048 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin

- 2009-07-14 05:10 . 2012-06-04 02:55 43084 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin

+ 2009-07-14 05:10 . 2012-06-04 04:28 43084 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin

+ 2011-11-01 02:20 . 2012-06-04 04:28 12732 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1816964637-4104116600-144631762-1001_UserData.bin

- 2012-06-04 02:53 . 2012-06-04 02:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2012-06-04 04:26 . 2012-06-04 04:26 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2012-06-04 04:26 . 2012-06-04 04:26 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

- 2012-06-04 02:53 . 2012-06-04 02:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

- 2009-07-14 05:01 . 2012-06-04 02:52 235700 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

+ 2009-07-14 05:01 . 2012-06-04 04:25 235700 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

- 2011-11-01 02:17 . 2012-06-04 02:52 2179964 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1816964637-4104116600-144631762-1001-8192.dat

+ 2011-11-01 02:17 . 2012-06-04 04:25 2179964 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1816964637-4104116600-144631762-1001-8192.dat

- 2009-07-14 02:34 . 2012-06-03 13:19 10223616 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT

+ 2009-07-14 02:34 . 2012-06-04 03:10 10223616 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]

c:\program files (x86)\uTorrentBar\prxtbuTor.dll [bU]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]

"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\prxtbuTor.dll" [bU]

.

[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"HPAdvisorDock"="c:\program files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe" [2010-02-10 1712184]

"LightScribe Control Panel"="c:\program files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" [2010-05-19 2736128]

"SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-06 2260480]

"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-11-10 3514176]

"Steam"="c:\program files (x86)\Steam\Steam.exe" [2012-05-05 1242448]

"Overwolf"="c:\program files (x86)\Overwolf\Overwolf.exe" [2012-05-10 42424]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-06-17 98304]

"HP Quick Launch"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" [2010-06-30 602168]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]

"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296]

"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]

"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]

"Monitor"="c:\program files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe" [2011-11-12 268640]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

"aux3"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

.

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-12-24 136176]

R2 HP Wireless Assistant Service;HP Wireless Assistant Service;c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2010-06-18 103992]

R2 RtVOsdService;RtVOsdService Installer;c:\program files\Realtek\RtVOsd\RtVOsdService.exe [2010-04-20 315392]

R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-12-24 136176]

R3 Leapfrog-USBLAN;Leapfrog-USBLAN;c:\windows\system32\DRIVERS\btblan.sys [x]

R3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [x]

R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]

R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-03-27 291696]

R3 OverwolfUpdaterService;Overwolf Updater Service;c:\program files (x86)\Overwolf\OverwolfUpdater.exe [2012-05-10 18360]

R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]

R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x]

R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x]

R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]

R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]

S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]

S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]

S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 98208]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]

S2 CinemaNow Service;CinemaNow Service;c:\program files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe [2010-05-21 140272]

S2 HPWMISVC;HPWMISVC;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2010-06-30 27192]

S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]

S2 RosettaStoneLtdController;RosettaStoneLtdController;c:\program files (x86)\RosettaStoneLtdServices\RosettaStoneLtdController.exe [2008-09-16 352312]

S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]

S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]

S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]

S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [x]

.

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]

2010-05-19 18:36 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe

.

Contents of the 'Scheduled Tasks' folder

.

2012-06-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-12-24 03:40]

.

2012-06-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-12-24 03:40]

.

2012-06-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1816964637-4104116600-144631762-1001Core.job

- c:\users\Sami\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-28 22:15]

.

2012-06-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1816964637-4104116600-144631762-1001UA.job

- c:\users\Sami\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-28 22:15]

.

2012-05-22 c:\windows\Tasks\HPCeeScheduleForSami.job

- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05 10:53]

.

.

--------- x86-64 -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [bU]

"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2010-05-26 6245408]

"HPWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe" [2010-06-18 8192]

"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-27 1271168]

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.yahoo.com/?ilc=17

uLocal Page = c:\windows\system32\blank.htm

mLocal Page = c:\windows\SysWOW64\blank.htm

IE: Download all with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlall.htm

IE: Download selected with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlselected.htm

IE: Download video with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlfvideo.htm

IE: Download with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dllink.htm

TCP: DhcpNameServer = 10.0.0.1

.

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11g_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11g_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11g.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.10"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11g.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11g.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11g.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

------------------------ Other Running Processes ------------------------

.

c:\program files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe

c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe

c:\program files (x86)\RosettaStoneLtdServices\RosettaStoneLtdServer.exe

c:\program files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe

c:\program files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe

c:\program files (x86)\Common Files\Steam\SteamService.exe

c:\program files (x86)\Common Files\Overwolf\OverwolfHelper.exe

.

**************************************************************************

.

Completion time: 2012-06-03 21:35:30 - machine was rebooted

ComboFix-quarantined-files.txt 2012-06-04 04:35

ComboFix2.txt 2012-06-04 03:03

.

Pre-Run: 70,054,621,184 bytes free

Post-Run: 69,621,493,760 bytes free

.

- - End Of File - - E77D91388C946E87B4821FE13521D3D3

Link to post
Share on other sites

Just before CF log popped up, MBAM (which I thought I had disabled) opened with a warning.

2012/06/03 06:07:52 -0700 SAMI-HP Sami MESSAGE Starting protection

2012/06/03 06:08:01 -0700 SAMI-HP Sami MESSAGE Protection started successfully

2012/06/03 06:08:05 -0700 SAMI-HP Sami MESSAGE Starting IP protection

2012/06/03 06:08:05 -0700 SAMI-HP Sami ERROR IP protection failed: FwpmEngineOpen0 failed with error code 1753

2012/06/03 13:25:18 -0700 SAMI-HP Sami MESSAGE Starting protection

2012/06/03 13:25:23 -0700 SAMI-HP Sami MESSAGE Protection started successfully

2012/06/03 13:25:26 -0700 SAMI-HP Sami MESSAGE Starting IP protection

2012/06/03 13:25:26 -0700 SAMI-HP Sami ERROR IP protection failed: FwpmEngineOpen0 failed with error code 1753

2012/06/03 19:56:31 -0700 SAMI-HP Sami MESSAGE Starting protection

2012/06/03 19:56:34 -0700 SAMI-HP Sami MESSAGE Protection started successfully

2012/06/03 19:56:37 -0700 SAMI-HP Sami MESSAGE Starting IP protection

2012/06/03 19:56:42 -0700 SAMI-HP Sami MESSAGE IP Protection started successfully

2012/06/03 21:28:54 -0700 SAMI-HP Sami MESSAGE Starting protection

2012/06/03 21:28:58 -0700 SAMI-HP Sami MESSAGE Protection started successfully

2012/06/03 21:29:01 -0700 SAMI-HP Sami MESSAGE Starting IP protection

2012/06/03 21:29:05 -0700 SAMI-HP Sami MESSAGE IP Protection started successfully

2012/06/03 21:34:27 -0700 SAMI-HP Sami DETECTION C:\Qoobox\Quarantine\C\Windows\assembly\GAC_32\Desktop.ini.vir Trojan.0access QUARANTINE

Did I quarantine ComboFix?

Link to post
Share on other sites

I think it just picked up what ComboFix had quaratined- shouldn't be anything, but if it keeps happening, let me know. ;)

Let's run an online scan to verify there aren't any traces left that we may have missed:

Please run a free online scan with the ESET Online Scanner

Note: You will need to use Internet Explorer for this scan.

  1. Tick the box next to YES, I accept the Terms of Use.
  2. Click Start
  3. When asked, allow the ActiveX control to install
  4. Click Start
  5. Make sure that the options Remove found threats is Unchecked and the option Scan unwanted applications is checked
  6. Click Scan
    Wait for the scan to finish
  7. Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  8. Copy and paste that log as a reply to this topic

Link to post
Share on other sites

<p> </p>

<div>K, this is the log file, which didn't seem right.</div>

<div> </div>

<div> </div>

<div>ESETSmartInstaller@High as CAB hook log:</div>

<div>OnlineScanner64.ocx - registred OK</div>

<div>OnlineScanner.ocx - registred OK</div>

<div> </div>

<div>And these are the results of the scan, which didn't save automatically.  This looks more up your alley <img alt=";)" class="bbc_emoticon" src="http://forums.malwarebytes.org/public/style_emoticons/default/wink.png" title=";)" /></div>

<div> </div>

<div>

<div>C:\FRST\Quarantine\{46aea556-3b27-4fe4-c5d6-735ab4da8640}\U\00000008.@<span class="Apple-tab-span" style="white-space:pre"> </span>Win64/Agent.BA trojan</div>

<div>C:\FRST\Quarantine\{46aea556-3b27-4fe4-c5d6-735ab4da8640}\U\80000000.@<span class="Apple-tab-span" style="white-space:pre"> </span>Win64/Sirefef.AE trojan</div>

<div>C:\FRST\Quarantine\{46aea556-3b27-4fe4-c5d6-735ab4da8640}\U\80000032.@<span class="Apple-tab-span" style="white-space:pre"> </span>probably a variant of Win32/Sirefef.EU trojan</div>

<div>C:\FRST\Quarantine\{46aea556-3b27-4fe4-c5d6-735ab4da8640}\U\80000064.@<span class="Apple-tab-span" style="white-space:pre"> </span>Win64/Sirefef.AE trojan</div>

<div>C:\Qoobox\Quarantine\C\Windows\assembly\GAC_64\Desktop.ini.vir<span class="Apple-tab-span" style="white-space:pre"> </span>Win64/Sirefef.AD trojan</div>

<div>C:\Users\Sami\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VKS0RCUE\71196[1].pdf<span class="Apple-tab-span" style="white-space:pre"> </span>JS/Exploit.Pdfka.PFS.Gen trojan</div>

<div>C:\Users\Sami\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\XAHK0JRA\1a67b[1].pdf<span class="Apple-tab-span" style="white-space:pre"> </span>JS/Exploit.Pdfka.PFS.Gen trojan</div>

<div>C:\Users\Sami\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\XAHK0JRA\2e2ab[1].pdf<span class="Apple-tab-span" style="white-space:pre"> </span>JS/Exploit.Pdfka.PFS.Gen trojan</div>

<div>C:\Users\Sami\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\XAHK0JRA\88f14[1].pdf<span class="Apple-tab-span" style="white-space:pre"> </span>JS/Exploit.Pdfka.PFS.Gen trojan</div>

<div>C:\Users\Sami\Downloads\dvdburning_1289.exe<span class="Apple-tab-span" style="white-space:pre"> </span>a variant of Win32/InstallIQ application</div>

<div> </div>

</div>

<div> </div>

<div> </div>

<div> </div>

Link to post
Share on other sites

I have no idea what has happened to formatting, sorry.

No worries, it happens. :lol:

The scan just picked up some of the items that we quaratined. Things are looking good! :)

Let's see what programs of yours need updating:

Please download Security Check by screen317 from here or here.

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

Link to post
Share on other sites

Results of screen317's Security Check version 0.99.41

Windows 7 x64 (UAC is enabled)

Out of date service pack!!

Internet Explorer 9

``````````````Antivirus/Firewall Check:``````````````

Windows Firewall Enabled!

WMI entry may not exist for antivirus; attempting automatic update.

`````````Anti-malware/Other Utilities Check:`````````

Spybot - Search & Destroy

Malwarebytes Anti-Malware version 1.61.0.1400

Java 6 Update 31

Java version out of date!

Adobe Reader 9 Adobe Reader out of date!

Google Chrome 19.0.1084.52

````````Process Check: objlist.exe by Laurent````````

Microsoft Security Essentials msseces.exe

Malwarebytes Anti-Malware mbamservice.exe

Malwarebytes Anti-Malware mbamgui.exe

ESET ESET Online Scanner OnlineCmdLineScanner.exe

`````````````````System Health check`````````````````

Total Fragmentation on Drive C: 0%

````````````````````End of Log``````````````````````

I'm not getting redirected with Chrome, and no more unsafe signatures from websites. So something good is happening!

Link to post
Share on other sites

I'm not getting redirected with Chrome, and no more unsafe signatures from websites. So something good is happening!

Yep, things are looking good. ;)

There is an update for Windows, but I can't install it. Husband is having the same problem on his clean machine.

See if you can download it as a standalone download to your machine, and install it that way rather than directly from Windows Updates. I've included the link below. Let me know if you encounter any trouble. :)

Before we move on, let's update some of your programs.

Program updates are a crucial step in preventing malware, as outdated applications are often used by the cybercriminals to gain a foothold on your system.

First,

:excl:Please consider updating to Windows 7 Service Pack 1 (SP1).

Windows 7 Service Pack 1 (SP1) contains many major updates released plus support for new types of hardware and emerging hardware standards.

It is now available via Windows Update or as a standalone installation here.

-----------

Java is out of date and older versions contain vulnerabilities. Please update to the newest version.

Download the newest version from here http://java.com/en/download/index.jsp.

It's important to remove older versions of Java since it does not do so automatically and old versions still leave you vulnerable.

Go to Start > Control Panel and open Add or Remove Programs.

Search in the list for all previous installed versions of Java. (J2SE Runtime Environment).

They will have this icon next to them: javaicon.gif

Select each in turn and click Remove.

Once old versions are gone, please install the newest version.

-----------

You're using an old version of Adobe Acrobat Reader, this can leave your PC open to vulnerabilities, you can update it here (uninstall version 7.0 first):

Adobe Reader X

Note: I suggest you uncheck an optional, third-party download (eg. McAfee Security Scan Plus).

After successfully installing Adobe Reader X, see this article on how to make this program more secure: Adobe Reader X secures itself by playing in the sandbox.

-----------

Let me know how the program updates go, as failed updates may be a sign of additional malware. ;)

Link to post
Share on other sites

Glad to hear that! :)

Unless there are any further issues, I will now provide you with some suggestions for security software.

First, let's remove ComboFix:

The following will implement some cleanup procedures as well as reset System Restore points:

Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

ComboFix /Uninstall

-------------

Please consider using these ideas to help secure your computer. While there is no way to guarantee safety when you use a computer, these steps will make it much less likely that you will need to endure another infection. While we really like to help people, we would rather help you protect yourself so that you won't need that help in the future. :)

Please either enable Automatic Updates under Start -> Control Panel -> Automatic Updates or get into the habit of checking Windows Update regularly. They usually have security updates every month. You can set Windows to notify you of Updates so that you can choose, but only do this if you believe you are able to understand which ones are needed. This is a crucial security measure.

It is really dangerous to go online without an antivirus. Without one, you are extremely likely to get infected and the consequences could be even worse next time. All of the following are excellent free antiviruses. Be sure to only install one.

avast!.

AntiVir

AVG

Please consider installing and running some of the following programs; they are either free or have free versions of commercial programs:

Spybot-Search & Destroy

A tutorial on using Spybot to remove spyware from your computer may be found here. Please also remember to enable Spybot's "Immunize" and "TeaTimer" features if you don't have the resident part of another anti-spyware program running.

SpywareBlaster

A tutorial on using SpywareBlaster to prevent malware from ever installing on your computer may be found here.

SpywareGuard

A tutorial on using SpywareGuard for real-time protection against spyware and hijackers may be found here.

Please, consider maintaining a firewall with HIPS (Host Intrusion Prevention Systems). Firewalls are extremely important and are the first part of your computer's defense. HIPS stops malware by monitoring its behavior and it's very important, too.

A firewall is a software program or piece of hardware that helps screen out hackers, viruses, and worms that try to reach your computer over the Internet.

If you are using the Windows Firewall please note that it doesn't monitor or block outbound traffic and is therefore less effective than other free alternatives.

These firewalls are good and do have free versions available

A tutorial on understanding and using firewalls may be found here.

If you use Internet Explorer, it is a good idea to use IE-Spyad for ZonedOut which provides protections against malicious websites. (Requires 2 downloads)

Please keep these programs up-to-date and run them whenever you suspect a problem to prevent malware problems. A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall and scanning anti-spyware program at a time. Passive protectors, like SpywareBlaster and IE-Spyad can be run with any of them.

Note that there are a lot of rogue programs out there that want to scare you into giving them your money and some malware actually claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on reviews and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here:

http://www.spywarewa...nti-spyware.htm

A similar category of programs is now called "scareware." Scareware programs are active infections that will pop-up on your computer and tell you that you are infected. If you look closely, it will usually have a name that looks like it might be legitimate, but it is NOT one of the programs you installed. It tells you to click and install it right away. If you click on any part of it, including the 'X' to close it, you may actually help it infect your computer further. Keeping protection updated and running resident protection can help prevent these infections. If it happens anyway, get offline as quickly as you can. Pull the internet connection cable or shut down the computer if you have to. Contact someone to help by using another computer if possible. These programs are also sometimes called 'rogues', but they are different than the older version of rogues mentioned above.

Please consider using an alternate browser. Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScripts, can make it even more secure. Opera is another good option.

If you are interested, Firefox may be downloaded from here

Opera is available here: http://www.opera.com/download/

For much more useful information, please also read Tony Klein's excellent article: How did I get infected in the first place

Hopefully these steps will help to keep you error free. If you run into more difficulty, we will certainly do what we can to help. :)

Link to post
Share on other sites

Glad to hear things are well! If you have any other questions or concerns, don't hesitate to ask. ;)

Otherwise, I will have this thread closed. You can still reach me by private message here on the site if you need anything. :)

Kind regards,

-DFB

Link to post
Share on other sites

Glad we could help. :)

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.