Jump to content

Riddle Me this batman.....


Recommended Posts

So here I am.

Obviously I have a problem with my computer and I need YOUR help.

What you should know:

-I have Malwarebytes, SuperAntiSpyware, Command AntiVirus, Spybot, Sygate Personal Firewall, & Ad-Aware on my laptop currently.

I know that's overkill. Tell me what to keep.

-Running XP

-Recently had everything deleted and XP reinstalled

The Problem:

Well, the problem is... I don't have a problem. I think.

By that i mean, nothing appears to be wrong. I'm having no issues with anything on my computer.

Yet, for some reason on 6 different occasions, a MalwareBytes scan found something called "Rogue.AntiVirus" in the registry keys category. Each has a different reference number but they're all called the same thing.

Registry Keys Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Antivirus (Rogue.AntiVirus)

-It tells me its been quarantined and removed each time.

-I'll go a day or two and do several more scans without it showing up again. Then out of nowhere, for what seems to be no apparent reason, the same thing comes back.

Im not sure what it is or why this keeps happening and i sure would like to.

-I have all the logs and reference #'s MBAM gave me if that helps.

Any help resolving this issue would be GREATLY appreciated!!

;)

Link to post
Share on other sites

**This may be confusing because this scan was one of the scans where nothing shows up...

It showed up again just yesterday. It shows up 6 different times in my "Quarantine" section each time with a different reference #***

When the log actually does show the infection, this is what it always says is there:

Registry Keys Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Antivirus (Rogue.AntiVirus)

Then MBAM claims to quarantine & remove it, but the same thing always seems to show up a few scans later...

-Below are the logs you asked for... I'm not sure if they will help or not because i don't think they found anything.

MBAM LOG:

Malwarebytes' Anti-Malware 1.41

Database version: 3245

Windows 5.1.2600 Service Pack 3

11/27/2009 4:24:19 PM

mbam-log-2009-11-27 (16-24-19).txt

Scan type: Quick Scan

Objects scanned: 98554

Time elapsed: 7 minute(s), 6 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

--------------------------------------------------------------------------------------------

HijackThis Log:

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 4:03:56 PM, on 11/27/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Sygate\SPF\smc.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\System32\igfxtray.exe

C:\WINDOWS\System32\hkcmd.exe

C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe

C:\Program Files\Authentium\Command AntiVirus\avinitnt.exe

C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe

C:\Program Files\Authentium\Command AntiVirus\schscnt.exe

C:\Program Files\Authentium\Command AntiVirus\dvprpt.exe

C:\Program Files\Authentium\Command AntiVirus\avtray.exe

C:\Program Files\Authentium\Command AntiVirus\untray.exe

C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe

C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = google.com

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\System32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe

O4 - HKLM\..\Run: [avtray] C:\PROGRA~1\AUTHEN~1\COMMAN~1\avtray.exe

O4 - HKLM\..\Run: [untray] C:\PROGRA~1\AUTHEN~1\COMMAN~1\untray.exe

O4 - HKLM\..\Run: [dvprpt] C:\PROGRA~1\AUTHEN~1\COMMAN~1\dvprpt.exe

O4 - HKLM\..\Run: [CSAV_CheckViruses] C:\PROGRA~1\AUTHEN~1\COMMAN~1\vchk.exe

O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

O4 - HKLM\..\Run: [smcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui

O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

O4 - S-1-5-18 Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe (User 'SYSTEM')

O4 - .DEFAULT Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe (User 'Default user')

O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1257970541923

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1257970533301

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: avinitnt - Authentium, Inc. - C:\Program Files\Authentium\Command AntiVirus\avinitnt.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe

O23 - Service: schscnt - Authentium, Inc. - C:\Program Files\Authentium\Command AntiVirus\schscnt.exe

O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe

--

End of file - 5019 bytes

Thanks for your help!!

:(

Link to post
Share on other sites

  • Staff

Hi,

When the log actually does show the infection, this is what it always says is there:

Registry Keys Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Antivirus (Rogue.AntiVirus)

Then MBAM claims to quarantine & remove it, but the same thing always seems to show up a few scans later...

I think I already know what is happening here. I see you have command Antivirus installed here and it wouldn't suprise me it creates the same keyname as the rogue.Antivirus has.

And that may explain why it always comes back afterwards, since Command Antivirus restores its key again.

Anyway, we have removed detection for that key for now, so Malwarebytes won't detect it anymore.

However, I still would like to have an export of that key, so I can have a look at it and verify it is really from your command Antivirus.

To do this, Open notepad and copy and paste next present in the quotebox in it:

regedit /e look.txt "HKEY_LOCAL_MACHINE\SOFTWARE\Antivirus"

start notepad look.txt

Save this as look.bat , choose to save as *all files and place it on your desktop.

It should look like this: bat.gif

Doubleclick on it and notepad should open.

Copy and paste the contents of it in your next reply.

Link to post
Share on other sites

  • Staff

Nothing under it. So can't say much here. But in either way, this key is harmless and I'm pretty sure your command antivirus created that one.

I just googled and found this thread:

http://forum.piriform.com/index.php?showto...amp;#entry95409

Same key there and s(he) has Command Antivirus installed.

Ccleaner (registry cleaning option in it) detected that key as orphaned (as it looks indeed like an orphaned key as there is no data under it) and deleted it, with as result that their Command Antivirus didn't work after reboot.

So in either way, you are ok here - it's set by Command Antivirus. We removed this detection in malwarebytes now. :(

Link to post
Share on other sites

Well thank you :(

You've been VERY helpful!

In my first post I listed what I'm currently using for protection:

Malwarebytes, SuperAntiSpyware, Command AntiVirus, Spybot, Sygate Personal Firewall, & Ad-Aware

I was also hoping to find out which of them i should keep and which to get rid of. Or, if I should get something completely different. Free would be the perfect price.

I'm also thinking command antivirus could go.

Tell me what you think.. You seem to have all the right answers.

Link to post
Share on other sites

  • Staff

Hi,

Since I work for Malwarebytes, it's obvious to tell you to keep mbam.

As for the other spywarescanners (SuperAntispyware, Spybot and Ad-aware), you can keep them as well since they don't interfere with eachother, but I wouldn't let all these different scanners startup with Windows, because it causes an extra slowdown. But I see this isn't the case here anyway, so you're ok there.

Yes, keep Sygate as your personal firewall.

For Command Antivirus - from what I've read so far, it isn't that great in detection, however that could have changed in a meanwhile, so who am I to judge, so, if you like it, keep it, if not, uninstall Command Antivirus and install another Antivirus instead. You can choose if you want a free one or not. You can find my recommendations on this page: http://users.telenet.be/bluepatchy/miekiemoes/Links.html

Hope this helps.

Link to post
Share on other sites

I'm DEFINITELY going to keep Malwarebytes. I love it, it works, and the staff is helpful.

I know I said that was the last question I'd bother you with.. but...

I want to get rid of some of the clutter. I don't think I need all programs I listed having.

If I only kept MBAM & Sygate, then download Avast, would I be protected?

Or would there be anything else you would suggest having to keep intruders out?

Thank you again.. you've been sooo helpful.

I promise this really is my last question!!

:)

Link to post
Share on other sites

  • Staff
If I only kept MBAM & Sygate, then download Avast, would I be protected?
That's a good idea.

You can also read my Prevention page with lots of info and tips how to prevent malware in the future.

And if you want to improve speed/system performance after malware removal, take a look here.

Extra note: Make sure your programs are up to date - because older versions may contain Security Leaks. To find out what programs need to be updated, please run the Secunia Software Inspector Scan. :)

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.