Jump to content

Help please!


Recommended Posts

Got infected with something bad... Had Gadcom and Virtumonde infections a few months ago, used Avast/Spybot/Manual Removal, have been fine since then until a day or two ago.

Scanned with spybot... it found a LOT of infections, but couldn't remove all of them. Used Malwarebytes Anti-Malware, it removed all but 2... HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\MS JUAN and HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\MS Track System. Also, wscntfy is constantly running in the task manager/processes tab. I cannot turn on automatic updates, and I get popups after typing things into searches/text boxes/etc.

Here is the last log from Malwarebytes Anti-Malware:

Malwarebytes' Anti-Malware 1.31

Database version: 1531

Windows 5.1.2600 Service Pack 3

12/23/2008 6:36:23 AM

mbam-log-2008-12-23 (06-36-23).txt

Scan type: Quick Scan

Objects scanned: 51515

Time elapsed: 2 minute(s), 14 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 2

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

Found a couple of similar threads on this site through google, scanned with Panda Active Scan, here is the log:

;*******************************************************************************

********************************************************************************

*

*******************

ANALYSIS: 2008-12-23 09:44:18

PROTECTIONS: 1

MALWARE: 14

SUSPECTS: 4

;*******************************************************************************

********************************************************************************

*

*******************

PROTECTIONS

Description Version Active Updated

;===============================================================================

================================================================================

=

===================

avast! antivirus 4.8.1296 [VPS 081222-0] 4.8.1296 Yes Yes

;===============================================================================

================================================================================

=

===================

MALWARE

Id Description Type Active Severity Disinfectable Disinfected Location

;===============================================================================

================================================================================

=

===================

00029434 spyware/virtumonde Spyware No 1 Yes No hkey_local_machine\software\microsoft\ms track system

00029434 spyware/virtumonde Spyware No 1 Yes No hkey_local_machine\software\microsoft\ms juan

00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\Richard\Cookies\richard@doubleclick[2].txt

00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Richard\Cookies\richard@statcounter[1].txt

00447475 Adware/InternetSpeedMonitor Adware No 0 Yes No C:\System Volume Information\_restore{A355B3B7-D367-4F92-97FE-2AC889E0831D}\RP234\A0097844.exe

00462916 Adware/XPAntivirusPro Adware No 0 Yes No C:\System Volume Information\_restore{A355B3B7-D367-4F92-97FE-2AC889E0831D}\RP234\A0097843.exe

00464258 Spyware/Virtumonde Spyware No 1 Yes No C:\System Volume Information\_restore{A355B3B7-D367-4F92-97FE-2AC889E0831D}\RP272\A0109305.exe

00492014 Spyware/Virtumonde Spyware No 1 Yes No C:\Documents and Settings\Richard\Local Settings\Temporary Internet Files\Content.IE5\SBCGWLPK\apstpldr.dll[1].htm

00519333 Application/Processor HackTools No 0 Yes No C:\Documents and Settings\Richard\My Documents\Installers\VirtumundoBeGone.exe

01895148 Malicious Packer SecRisk No 0 No No D:\My Documents\Finished Torrents\Misc Programs\DAEMON Tools Pro ADVANCED v4.10.Build218.0\DTPro4100218Advanced.exe[D:\My Documents\Finished Torrents\Misc Programs\DAEMON Tools Pro ADVANCED v4.10.Build218.0\DTPro4100218Advanced.exe][is153343.exe]

02921148 Adware/AccesMembre Adware No 0 No No D:\My Documents\Finished Torrents\Misc Programs\Photoshop CS3_Extended (Keygen+ Crack!)\Photoshop CS3 Keygen + Crack\Keygen + Activation Key\PhotoShop CS3 Extended Keygen + Activationxx.EXE[D:\My Documents\Finished Torrents\Misc Programs\Photoshop CS3_Extended (Keygen+ Crack!)\Photoshop CS3 Keygen + Crack\Keygen + Activation Key\PhotoShop CS3 Extended Keygen + Activationxx.EXE][WINDOW~1.EXE]

02921148 Adware/AccesMembre Adware No 0 No No D:\My Documents\Finished Torrents\Misc Programs\Photoshop CS3_Extended (Keygen+ Crack!)\Photoshop CS3 Keygen + Crack\Crack (optional only if u cant do keygen)\Adobe PhotoShop CS3 EXTENDEDxx.EXE[D:\My Documents\Finished Torrents\Misc Programs\Photoshop CS3_Extended (Keygen+ Crack!)\Photoshop CS3 Keygen + Crack\Crack (optional only if u cant do keygen)\Adobe PhotoShop CS3 EXTENDEDxx.EXE][WINDOW~1.EXE]

02925267 Generic Trojan Virus/Trojan No 0 Yes No D:\System Volume Information\_restore{1106BC17-AB10-43A3-A029-5942B86D4B2E}\RP292\A0086292.exe

03275032 Generic Malware Virus/Trojan No 0 Yes No C:\GMOD10\GMod10[Final].exe

03277754 Generic Trojan Virus/Trojan No 0 Yes No C:\Documents and Settings\Richard\My Documents\VAMPIRE.TM.B.V1.2.PLUS3TRN.RIP.ZIP[VampireBloodlinesTrainer_RIP.exe]

04438488 Spyware/Virtumonde Spyware No 1 Yes No C:\WINDOWS\system32\arorzs.dll

04438488 Spyware/Virtumonde Spyware No 1 Yes No C:\WINDOWS\System32\arorzs.dll

04438488 Spyware/Virtumonde Spyware No 1 Yes No C:\WINDOWS\system32\jwkkcuav.dll

04438488 Spyware/Virtumonde Spyware No 1 Yes No C:\WINDOWS\system32\arorzs.dll

;===============================================================================

================================================================================

=

===================

SUSPECTS

Sent Location

;===============================================================================

================================================================================

=

===================

No C:\Documents and Settings\Richard\My Documents\Installers\burnsetupcnet.exe

No C:\WINDOWS\system32\urqRKCrQ.dll

No D:\My Documents\Finished Torrents\Misc Programs\Photoshop CS3_Extended (Keygen+ Crack!)\Photoshop CS3 Keygen + Crack\Crack (optional only if u cant do keygen)\Adobe PhotoShop CS3 EXTENDEDxx.EXE[D:\My Documents\Finished Torrents\Misc Programs\Photoshop CS3_Extended (Keygen+ Crack!)\Photoshop CS3 Keygen + Crack\Crack (optional only if u cant do keygen)\Adobe PhotoShop CS3 EXTENDEDxx.EXE][ADOBEP~1.EXE]

No D:\System Volume Information\_restore{B71F70FD-EDFA-444B-B154-A85940DC645B}\RP4\A0000214.exe[

Link to post
Share on other sites

01895148 Malicious Packer SecRisk No 0 No No D:\My Documents\Finished Torrents\Misc Programs\DAEMON Tools Pro ADVANCED v4.10.Build218.0\DTPro4100218Advanced.exe[D:\My Documents\Finished Torrents\Misc Programs\DAEMON Tools Pro ADVANCED v4.10.Build218.0\DTPro4100218Advanced.exe][is153343.exe]02921148 Adware/AccesMembre Adware No 0 No No D:\My Documents\Finished Torrents\Misc Programs\Photoshop CS3_Extended (Keygen+ Crack!)\Photoshop CS3 Keygen + Crack\Keygen + Activation Key\PhotoShop CS3 Extended Keygen + Activationxx.EXE[D:\My Documents\Finished Torrents\Misc Programs\Photoshop CS3_Extended (Keygen+ Crack!)\Photoshop CS3 Keygen + Crack\Keygen + Activation Key\PhotoShop CS3 Extended Keygen + Activationxx.EXE][WINDOW~1.EXE]02921148 Adware/AccesMembre Adware No 0 No No D:\My Documents\Finished Torrents\Misc Programs\Photoshop CS3_Extended (Keygen+ Crack!)\Photoshop CS3 Keygen + Crack\Crack (optional only if u cant do keygen)\Adobe PhotoShop CS3 EXTENDEDxx.EXE[D:\My Documents\Finished Torrents\Misc Programs\Photoshop CS3_Extended (Keygen+ Crack!)\Photoshop CS3 Keygen + Crack\Crack (optional only if u cant do keygen)\Adobe PhotoShop CS3 EXTENDEDxx.EXE][WINDOW~1.EXE]

Shows you got more than photoshop, you got a nice virus too. Again, you must remove cracked software before we can help. It's out policy, and most forums software.

Link to post
Share on other sites

  • Root Admin

HiJack This! Forum Policy

We will not be party to obvious use of key gens, cracks, warez or other illegal means of downloading software, music, videos ect. This means no P2P evidence will be supported. Logs that show these in them, will given the option to remove the P2P items.
Keygens, cracks, warez and similar will have the thread closed period. It's theft and against the law.
Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.