Jump to content

Infected with Poweliks


AEITS

Recommended Posts

HKU\S-1-5-21-3542812387-3794330035-1786331983-1003\...\Run: [ivijios] => rundll32 "C:\Users\Gary_2\AppData\Local\ivijios.dll",ivijios <===== ATTENTION

HKU\S-1-5-21-3542812387-3794330035-1786331983-1003\...\Run: [Olfoegbaba] => C:\Users\Gary_2\AppData\Roaming\Paquyru\siami.exe

HKU\S-1-5-21-3542812387-3794330035-1786331983-1003\...A8F59079A8D5}\localserver32: rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 239 more characters). <==== Poweliks!

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION

HKU\S-1-5-21-3542812387-3794330035-1786331983-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION

CustomCLSID: HKU\S-1-5-21-3542812387-3794330035-1786331983-1003_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32 -> rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 247 more characters). <==== Poweliks?

Link to post
Share on other sites

Didn't see an attached fixlist, so I ran mine. It still didn't find one of the keys. I found it with regedit. I did a search for "rundll32.exe javascript", and deleted any keys I found. I found the remaining one, and it's gone now.

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 08-11-2014 01

Ran by admin at 2014-11-09 01:06:20 Run:1

Running from C:\Users\Gary_2\Desktop

Loaded Profiles: admin & Gary_2 (Available profiles: admin & Gary & Gary_2)

Boot Mode: Normal

==============================================

Content of fixlist:

*****************

HKU\S-1-5-21-3542812387-3794330035-1786331983-1003\...\Run: [ivijios] => rundll32 "C:\Users\Gary_2\AppData\Local\ivijios.dll",ivijios <===== ATTENTION

HKU\S-1-5-21-3542812387-3794330035-1786331983-1003\...\Run: [Olfoegbaba] => C:\Users\Gary_2\AppData\Roaming\Paquyru\siami.exe

HKU\S-1-5-21-3542812387-3794330035-1786331983-1003\...A8F59079A8D5}\localserver32: rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 239 more characters). <==== Poweliks!

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION

HKU\S-1-5-21-3542812387-3794330035-1786331983-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION

CustomCLSID: HKU\S-1-5-21-3542812387-3794330035-1786331983-1003_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32 -> rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 247 more characters). <==== Poweliks?

*****************

HKU\S-1-5-21-3542812387-3794330035-1786331983-1003\Software\Microsoft\Windows\CurrentVersion\Run\\ivijios => value deleted successfully.

HKU\S-1-5-21-3542812387-3794330035-1786331983-1003\Software\Microsoft\Windows\CurrentVersion\Run\\Olfoegbaba => value deleted successfully.

"HKU\S-1-5-21-3542812387-3794330035-1786331983-1003\Software\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32" => Key Deleted Successfully.

"HKU\S-1-5-21-3542812387-3794330035-1786331983-1003\Software\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}" => Key deleted successfully.

"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.

"HKU\S-1-5-21-3542812387-3794330035-1786331983-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.

"HKU\S-1-5-21-3542812387-3794330035-1786331983-1003_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}" => Key not found.

==== End of Fixlog ====

Link to post
Share on other sites

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 08-11-2014 01

Ran by admin at 2014-11-09 11:12:38 Run:2

Running from C:\Users\Gary_2\Desktop

Loaded Profiles: admin & Gary_2 (Available profiles: admin & Gary & Gary_2)

Boot Mode: Normal

==============================================

Content of fixlist:

*****************

HKU\S-1-5-21-3542812387-3794330035-1786331983-1003\...\Run: [ivijios] => rundll32 "C:\Users\Gary_2\AppData\Local\ivijios.dll",ivijios <===== ATTENTION

HKU\S-1-5-21-3542812387-3794330035-1786331983-1003\...\Run: [Olfoegbaba] => C:\Users\Gary_2\AppData\Roaming\Paquyru\siami.exe

HKU\S-1-5-21-3542812387-3794330035-1786331983-1003\...A8F59079A8D5}\localserver32: rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 239 more characters). <==== Poweliks!

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION

HKU\S-1-5-21-3542812387-3794330035-1786331983-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION

2014-10-30 17:30 - 2014-10-30 17:51 - 00000000 ____D () C:\20141024

CustomCLSID: HKU\S-1-5-21-3542812387-3794330035-1786331983-1003_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32 -> rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 247 more characters). <==== Poweliks?

C:\Users\Gary_2\AppData\Local\ivijios.dll

C:\Users\Gary_2\AppData\Roaming\Paquyru

*****************

HKU\S-1-5-21-3542812387-3794330035-1786331983-1003\Software\Microsoft\Windows\CurrentVersion\Run\\ivijios => Value not found.

HKU\S-1-5-21-3542812387-3794330035-1786331983-1003\Software\Microsoft\Windows\CurrentVersion\Run\\Olfoegbaba => Value not found.

"HKU\S-1-5-21-3542812387-3794330035-1786331983-1003\Software\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32" => Key not found.

"HKU\S-1-5-21-3542812387-3794330035-1786331983-1003\Software\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}" => Key not found.

"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key not found.

"HKU\S-1-5-21-3542812387-3794330035-1786331983-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key not found.

C:\20141024 => Moved successfully.

"HKU\S-1-5-21-3542812387-3794330035-1786331983-1003_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}" => Key not found.

"C:\Users\Gary_2\AppData\Local\ivijios.dll" => File/Directory not found.

"C:\Users\Gary_2\AppData\Roaming\Paquyru" => File/Directory not found.

==== End of Fixlog ====

Link to post
Share on other sites

Would you do me a favor and run this scan:

Please download SystemLook from the link below and save it to your Desktop.

http://jpshortstuff.247fixes.com/SystemLook_x64.exe

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:

    :regfindAB8902B4-09CA-4bb6-B78D-A8F59079A8D5
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

MrC

Link to post
Share on other sites

SystemLook 30.07.11 by jpshortstuff

Log created at 12:28 on 09/11/2014 by admin

Administrator - Elevation successful

========== regfind ==========

Searching for "AB8902B4-09CA-4bb6-B78D-A8F59079A8D5"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}]

"AppID"="{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}]

"AppID"="{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}]

"AppID"="{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}]

-= EOF =-

Link to post
Share on other sites

  • 3 weeks later...
  • Root Admin

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.