Jump to content

Malwarebytes

Hijacked Search results and browser shutting

- - - - -

62 replies to this topic

#1
scipilot

    New Member

  • Members
  • Pip
  • 46 posts
Really do appreciate your help guys, I have had a search result hijack for ages now, tried all the usual and even lost £125 with a (well known) rip off Amercan company but getting knowhere fast.

I cant update Malwarebytes as the page closes when I click update. Also typing related words for virus removal will close my browser down.

Below is the Hijack This result with the Malwarebytes results below that.

Thanks.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:25:50, on 25/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
C:\Program Files\Common Files\AOL\1237591881\ee\AOLSoftware.exe
C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICLE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AOL 9.0\aoltray.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\arservice.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe
C:\HP\KBD\KBD.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\AOL 9.0\waol.exe
C:\Program Files\AOL 9.0\shellmon.exe
C:\Program Files\Common Files\AOL\aoltpspd.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\AVG\AVG8\aAvgApi.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Corel File Shell Monitor] C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1237591881\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Corel Photo Downloader] "C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe" -startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [EPSON Stylus Photo RX585 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICLE.EXE /FU "C:\WINDOWS\TEMP\E_SCD.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1237500532609
O17 - HKLM\System\CCS\Services\Tcpip\..\{8C31299D-2277-43D1-A029-4B46F7A00FD4}: NameServer = 205.188.146.145
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O24 - Desktop Component 0: (no name) - http://www.vistax64.com/clientscript/vbull...global.js?v=380

--
End of file - 11437 bytes

-
-
-
-


Malwarebytes' Anti-Malware 1.34
Database version: 1893
Windows 5.1.2600 Service Pack 3

25/03/2009 10:32:42
mbam-log-2009-03-25 (10-32-42).txt

Scan type: Quick Scan
Objects scanned: 93727
Time elapsed: 10 minute(s), 39 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Again many thank for any assisance.

#2
Fatdcuk

    Malware BBQ'er

  • Moderators
  • PipPipPipPipPipPip
  • 16,158 posts
  • Gender:Male
  • Location:127.0.0.1
Hi ya,

I need you to run a couple of tools for me and post back all logs :(

1)STEP 01
[indent]Please visit this webpage for instructions for downloading ComboFix to your DESKTOP : how-to-use-combofix
Please ensure you read this guide carefully and install the Recovery Console first.
NOTE!!: You must save and run ComboFix.exe on your DESKTOP and not from any other folder.
Also, DO NOT click the mouse or launch any other applications while this is running or it may stall the program

Additional links to download the tool:
ComboFix.exe
ComboFix.exe
ComboFix.exe


Note: The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

Once installed, you should see a blue screen prompt that says:

The Recovery Console was successfully installed.

Please continue as follows:
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Click Yes to allow ComboFix to continue scanning for malware.
  • When the tool is finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt along with a new HijackThis log so we may continue cleaning the system.
[/indent]


2)Please download GooredFix and save it to your Desktop.
http://jpshortstuff....m/GooredFix.exe
Select "2. Fix Goored" by typing 2 and pressing Enter.
Make sure all instances of Firefox are closed at this point.
Type y at the prompt and press Enter again.
A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called GooredLog.txt).
Note: If you receive a message saying that GooredFix needs your system to be restarted, please close all applications and reboot your system. Please also allow any registry changes that may be prompted by any of your security programs.
Ade Gill
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#3
scipilot

    New Member

  • Members
  • Pip
  • 46 posts
Hi and thanks for your help.

1st problem I have is trying to read the how to use instructions for combofix, clicking the link you added above 'how-to-use-combofix' closers my broswer, tried copying the url into AOL and that completly shuts AOL down. :(

#4
Fatdcuk

    Malware BBQ'er

  • Moderators
  • PipPipPipPipPipPip
  • 16,158 posts
  • Gender:Male
  • Location:127.0.0.1
Ok go with the GooredFix first :(
Ade Gill
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#5
scipilot

    New Member

  • Members
  • Pip
  • 46 posts
Done, see report below:


GooredFix v1.92 by jpshortstuff
Log created at 23:01 on 25/03/2009 running Option #2 (Compaq_Administrator)
Firefox version 3.0.7 (en-GB)

=====Goored Deletions=====

=====Dumping Registry Values=====

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.7\extensions]
"Plugins"="C:\Program Files\Mozilla Firefox\plugins"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.7\extensions]
"Components"="C:\Program Files\Mozilla Firefox\components"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"jqs@sun.com"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{1d5287d1-8a92-0001-1f31-1cec198018d8}"="C:\Program Files\AVG\AVG8\ToolbarFF"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{3f963a5b-e555-4543-90e2-c3908898db71}"="C:\Program Files\AVG\AVG8\Firefox"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{20a82645-c095-46ed-80e3-08825760534b}"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\"

#6
Fatdcuk

    Malware BBQ'er

  • Moderators
  • PipPipPipPipPipPip
  • 16,158 posts
  • Gender:Male
  • Location:127.0.0.1
Lets try again with Combofix run but this time use InternetExplorer as browser and not the AOL browser.
Ade Gill
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#7
scipilot

    New Member

  • Members
  • Pip
  • 46 posts
Tried again using I.E still closes the browser.

Thanks.

#8
scipilot

    New Member

  • Members
  • Pip
  • 46 posts
Got in via another PC, will post report when done as requested.

#9
scipilot

    New Member

  • Members
  • Pip
  • 46 posts
OK, got the instructions from another PC, followed then:

- closed all anti virus programmes and windows firewall

- downloaded ComboFix to my desktop

- closed all windows and double clicked ComboFix

- Clicked Run

I now get this message ' Errors encountered while performing the operation Look at the information window for more details. If I click OK there is just a small box with ComboFix written above a row of green lines.

Reboot is needed to clear it.

#10
Fatdcuk

    Malware BBQ'er

  • Moderators
  • PipPipPipPipPipPip
  • 16,158 posts
  • Gender:Male
  • Location:127.0.0.1
Ok something definetly not letting me unpack my toolkit on your pc but hey i love a challenge :(

Time to bring is some powerful tools and see if we can crack it!

1) Download the following tool and only use as directed!
http://rootrepeal.googlepages.com/

Install RootRepeal and select *Report* scan only.Next place tick in all box's except for SSDT report.Next press scan and then save the log generated.

Please Copy and Paste the output log generated in a reply post.


2nd report log needed-

Download and install Autoruns.
http://technet.microsoft.com/en-us/sysinte...s/bb963902.aspx

When you first run it it will generate an extensive listing and the word "Ready" will appear in the bottom left of the sofware GUI.
At this point goto options and place check(tick) against verify coded signatures and hide Microsoft & windows entries.Next press F5 button to refresh.

Once Ready status by software is gained then goto File option.Select "Export as" and save output file as Autoruns.txt

Can you please then copy and paste the contents of that text file into your next reply for analysis.
Ade Gill
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#11
scipilot

    New Member

  • Members
  • Pip
  • 46 posts
Attached File  Image1.jpg   16.28K   29 downloadsOK, stuck on the 1st hurdle again downloaded rootrepeal but see no *Report* option etc, see image.

1) Download the following tool and only use as directed!
http://rootrepeal.googlepages.com/

Install RootRepeal and select *Report* scan only.Next place tick in all box's except for SSDT report.Next press scan and then save the log generated.

#12
Fatdcuk

    Malware BBQ'er

  • Moderators
  • PipPipPipPipPipPip
  • 16,158 posts
  • Gender:Male
  • Location:127.0.0.1
Hi you need to extract rootrepeal and then run rootrepeal.exe :(

Attached File  rootrepeal.jpg   36.36K   22 downloads
Ade Gill
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#13
scipilot

    New Member

  • Members
  • Pip
  • 46 posts

Quote

you need to extract rootrepeal and then run rootrepeal.exe
Sorry having a dumb blonde day, not seeing your screen and can't see how to extract :(

#14
Fatdcuk

    Malware BBQ'er

  • Moderators
  • PipPipPipPipPipPip
  • 16,158 posts
  • Gender:Male
  • Location:127.0.0.1
No worries.

Download and save file from link to your desktop.
Next right click on file and select extract(Winrar) and then confirm(OK).
This will create new folder on desktop that has been decompressed from the downloaded file.Go into that folder and click on Rootrepeal .exe to run it .
Ade Gill
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#15
scipilot

    New Member

  • Members
  • Pip
  • 46 posts
Attached File  rootp_image.jpg   53.7K   26 downloads


OK, figured that out by searching your forum :(

Now I see this when double clicking the extraced rootrepeal file. (got any headache tablets) ?

#16
scipilot

    New Member

  • Members
  • Pip
  • 46 posts
OK, I went throught the process again, this time I clicked the 'OK' button and cleared the box above, clicked' Reports' then SCAN then selected as you have in your image.

POP PC switched off and rebooted back to my desktop :(

#17
scipilot

    New Member

  • Members
  • Pip
  • 46 posts
Right I took the bit between the teeth are retried, See log below :(

ROOTREPEAL © AD, 2007-2008
==================================================
Scan Time: 2009/03/26 20:10
Program Version: Version 1.2.3.0
Windows Version: Windows XP Media Center Edition SP3
==================================================

Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xF2C9E000 Size: 98304 File Visible: No
Status: -

Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7AF2000 Size: 8192 File Visible: No
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xB9B65000 Size: 45056 File Visible: No
Status: -

Hidden/Locked Files
-------------------
Path: C:\Documents and Settings\All Users\Application Data\AOL\storage\server.lock
Status: Allocation size mismatch (API: 8, Raw: 0)

Path: C:\Documents and Settings\Compaq_Administrator\Local Settings\Apps\2.0\CL0Z8EA0.Y16\320N6JQ6.BXA\manifests\clickonce_bootstrap.exe.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Compaq_Administrator\Local Settings\Apps\2.0\CL0Z8EA0.Y16\320N6JQ6.BXA\manifests\clickonce_bootstrap.exe.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Compaq_Administrator.YOUR-E6F02835AE\Local Settings\Apps\2.0\ERQX1MV9.4O5\W43NXRKK.C30\manifests\clickonce_bootstrap.exe.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Compaq_Administrator.YOUR-E6F02835AE\Local Settings\Apps\2.0\ERQX1MV9.4O5\W43NXRKK.C30\manifests\clickonce_bootstrap.exe.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Compaq_Administrator.YOUR-E6F02835AE\My Documents\Work\private audits\Spirita Limited\Completed DDA Audits\DDA 21 Trinity RD + Hall Rd + Bradley Crt\DDA 21 Trinity Rd + Hall Rd + Bradley Court\Bradley Court images\Thumbs.db:encryptable
Status: Locked to the Windows API!

#18
Fatdcuk

    Malware BBQ'er

  • Moderators
  • PipPipPipPipPipPip
  • 16,158 posts
  • Gender:Male
  • Location:127.0.0.1
Ok well no Rootkits showing up in that log :(

Please check your message box :(
Ade Gill
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#19
Fatdcuk

    Malware BBQ'er

  • Moderators
  • PipPipPipPipPipPip
  • 16,158 posts
  • Gender:Male
  • Location:127.0.0.1
Ok from the Autoruns log there was one suspicious entry.

MHNDRV Multimedia Home Network component driver (Not verified) Microsoft Corporation c:\windows\system32\drivers\mhndrv.sys

If possible could you locate and upload the file to VirusTotal service for 39 second opinions :(
http://www.virustotal.com
Please post back a link to the generated report page.

Also please attempt to download ComboFix via Firefox but using the following method.
Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
  • If you are using Firefox, make sure that your download settings are as follows:
    • Tools->Options->Main tab
    • Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

    Posted Image

    Posted Image


  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    -----------------------------------------------------------

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      -----------------------------------------------------------

    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    -----------------------------------------------------------

  • Double click on combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the "C:\Combo-Fix.txt" along with a new HijackThis log for further review.
**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**

If you still cannot get this to run, try booting into Safe Mode, and run it there.

To boot into Safe Mode, tap F8 after BIOS, and just before the Windows logo appears. A list of options will appear, select "Safe Mode."
Ade Gill
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#20
scipilot

    New Member

  • Members
  • Pip
  • 46 posts

Quote

If possible could you locate and upload the file to VirusTotal service for 39 second opinions
Please see below, will now go back to your post to continue.

File mhndrv.sys received on 02.26.2009 11:30:32 (CET)
Current status: finished

Result: 0/39 (0.00%)
Compact Print results
Antivirus Version Last Update Result
a-squared 4.0.0.93 2009.02.26 -
AhnLab-V3 2009.2.26.0 2009.02.25 -
AntiVir 7.9.0.88 2009.02.26 -
Authentium 5.1.0.4 2009.02.25 -
Avast 4.8.1335.0 2009.02.25 -
AVG 8.0.0.237 2009.02.26 -
BitDefender 7.2 2009.02.26 -
CAT-QuickHeal 10.00 2009.02.26 -
ClamAV 0.94.1 2009.02.25 -
Comodo 986 2009.02.20 -
DrWeb 4.44.0.09170 2009.02.26 -
eSafe 7.0.17.0 2009.02.25 -
eTrust-Vet 31.6.6375 2009.02.26 -
F-Prot 4.4.4.56 2009.02.25 -
F-Secure 8.0.14470.0 2009.02.26 -
Fortinet 3.117.0.0 2009.02.26 -
GData 19 2009.02.26 -
Ikarus T3.1.1.45.0 2009.02.26 -
K7AntiVirus 7.10.647 2009.02.25 -
Kaspersky 7.0.0.125 2009.02.26 -
McAfee 5536 2009.02.25 -
McAfee+Artemis 5536 2009.02.25 -
Microsoft 1.4306 2009.02.26 -
NOD32 3890 2009.02.26 -
Norman 6.00.06 2009.02.25 -
nProtect 2009.1.8.0 2009.02.26 -
Panda 10.0.0.10 2009.02.26 -
PCTools 4.4.2.0 2009.02.25 -
Prevx1 V2 2009.02.26 -
Rising 21.18.32.00 2009.02.26 -
SecureWeb-Gateway 6.0.0 2009.02.26 -
Sophos 4.39.0 2009.02.26 -
Sunbelt 3.2.1858.2 2009.02.25 -
Symantec 10 2009.02.26 -
TheHacker 6.3.2.5.265 2009.02.25 -
TrendMicro 8.700.0.1004 2009.02.26 -
VBA32 3.12.10.0 2009.02.26 -
ViRobot 2009.2.26.1624 2009.02.26 -
VirusBuster 4.5.11.0 2009.02.25 -
Additional information
File size: 11008 bytes
MD5...: 7f2f1d2815a6449d346fcccbc569fbd6
SHA1..: 3085859db0bf86a7014c1222321d68b0605768dd
SHA256: 1c5a321ce95ce4d9aa2cb5a00e9b7e711521a6bbb25d36f7f49a397c361585c6
SHA512: fd1cc04ebe6043f5fcee6fe5bc57185b050f07a88b8c1dba7d60d292b929bdcb
bfaf1c0c93e5d4fcd537b939d8b11ca46c065fd8b6006a8d5f2ff0847e9364e8
ssdeep: 192:6L9DvB9rtRzH8chmCWnh6RIBLQsOyh8iOIoJRaO0LmCsW1pvvW5DXVmVw:6L
1vB9rrccWzZtlh0dJRh+/sW1pvvWe

PEiD..: -
TrID..: File type identification
Generic Win/DOS Executable (49.9%)
DOS Executable Generic (49.8%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x12085
timedatestamp.....: 0x4118a72e (Tue Aug 10 10:45:02 2004)
machinetype.......: 0x14c (I386)

( 6 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x300 0x1af4 0x1b00 6.24 e85d995947c2851c7b7da2fa6ab865df
.rdata 0x1e00 0x1a4 0x200 3.13 1e44126c3497709bada215832493fd75
.data 0x2000 0x44 0x80 0.38 0c41a08c90a7d5e81bf065649ebabedc
INIT 0x2080 0x32a 0x380 4.98 eac5e44018d7b0f8ed40eed75a287e33
.rsrc 0x2400 0x440 0x480 3.31 1fd1baf851cca727b2ec3ee4fbb367bc
.reloc 0x2880 0x248 0x280 5.79 d40d025ca4fa1787c2f6b0336a028023

( 2 imports )
> ntoskrnl.exe: KeInitializeSpinLock, IoCreateDevice, RtlInitUnicodeString, MmUnlockPages, IoFreeMdl, ExAllocatePoolWithQuotaTag, _except_handler3, IoReleaseCancelSpinLock, IoAcquireCancelSpinLock, ExFreePoolWithTag, KeAcquireInStackQueuedSpinLockAtDpcLevel, MmMapLockedPagesSpecifyCache, MmProbeAndLockPages, IoAllocateMdl, ProbeForWrite, SeSinglePrivilegeCheck, SeExports, KeTickCount, IoDeleteDevice, KeReleaseInStackQueuedSpinLockFromDpcLevel, IofCompleteRequest
> HAL.dll: KeReleaseInStackQueuedSpinLock, KeAcquireInStackQueuedSpinLock

( 0 exports )





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us