Hello,
I posted on Sept. 11 about a Taskman registry agent that re-creates itself after deletion (link). An update was generated to eliminate the malware, and it seemed to fix the issue quite well. Unfortunately, the registry agent seems to have reappeared on my system as of this afternoon.
I downloaded the latest MBAM update, scanned and cleaned up infected items, re-booted and then re-scanned. One registry value keeps reappearing. I am hoping that nothing was missed the last time. I have scanned the system numerous times since the last time I posted, and nothing unusual came up (until today, that is).
Here is the log entry:
Malwarebytes' Anti-Malware 1.41
Database version: 2865
Windows 5.1.2600 Service Pack 3
9/27/2009 8:32:52 PM
mbam-log-2009-09-27 (20-32-52).txt
Scan type: Quick Scan
Objects scanned: 138293
Time elapsed: 14 minute(s), 30 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Any advice on how to remove this item would be greatly appreciated!
#1
Posted 28 September 2009 - 12:47 AM
#2
Posted 28 September 2009 - 02:56 AM
I re-ran the export.zip file and am attaching the result. Hopefully this wil help speed up the process.
Attached Files
#3
Posted 28 September 2009 - 12:13 PM
Thanks Neuro,
I will be adding new signature to attack your variant of the autorun worm shortly
I will be adding new signature to attack your variant of the autorun worm shortly
#4
Posted 28 September 2009 - 02:50 PM
Hi neuro,
Please update and run MBAM quick scan,allow it to delete what it finds and then reboot!
Please then run quick scan again to confirm that we have unloaded your variant.
Thanks in advance
Please update and run MBAM quick scan,allow it to delete what it finds and then reboot!
Please then run quick scan again to confirm that we have unloaded your variant.
Thanks in advance
#5
Posted 28 September 2009 - 05:01 PM
Unfortunately, the registry value is still there after scan and re-boot.
Here is the log file:
Malwarebytes' Anti-Malware 1.41
Database version: 2867
Windows 5.1.2600 Service Pack 3
9/28/2009 12:58:44 PM
mbam-log-2009-09-28 (12-58-44).txt
Scan type: Quick Scan
Objects scanned: 137905
Time elapsed: 11 minute(s), 59 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Any ideas??
Here is the log file:
Malwarebytes' Anti-Malware 1.41
Database version: 2867
Windows 5.1.2600 Service Pack 3
9/28/2009 12:58:44 PM
mbam-log-2009-09-28 (12-58-44).txt
Scan type: Quick Scan
Objects scanned: 137905
Time elapsed: 11 minute(s), 59 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Any ideas??
#6
Posted 28 September 2009 - 05:16 PM
Hi,
Please rerun quick scan when we update to database 2868.
Thanks in advance
Please rerun quick scan when we update to database 2868.
Thanks in advance
#7
Posted 28 September 2009 - 05:27 PM
Here it is.
Attached Files
#8
Posted 28 September 2009 - 06:13 PM
I ran MBAM with the latest update. It picked up an additional file to delete on re-boot. I am about to repeat the scan, so hopefully everything will come up clean.
Here is the log file:
Malwarebytes' Anti-Malware 1.41
Database version: 2868
Windows 5.1.2600 Service Pack 3
9/28/2009 2:03:00 PM
mbam-log-2009-09-28 (14-02-59).txt
Scan type: Quick Scan
Objects scanned: 138070
Time elapsed: 11 minute(s), 52 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\RECYCLER\S-1-5-21-3127580010-4974886753-998515483-7444\wmiprvse.exe (Worm.Autorun.
-> Delete on reboot.
Here is the log file:
Malwarebytes' Anti-Malware 1.41
Database version: 2868
Windows 5.1.2600 Service Pack 3
9/28/2009 2:03:00 PM
mbam-log-2009-09-28 (14-02-59).txt
Scan type: Quick Scan
Objects scanned: 138070
Time elapsed: 11 minute(s), 52 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\RECYCLER\S-1-5-21-3127580010-4974886753-998515483-7444\wmiprvse.exe (Worm.Autorun.
#9
Posted 28 September 2009 - 06:33 PM
The latest scan came up clean, so I hope that means it's taken care of. As I mentioned in the first post of this topic, I was having the same issue on Sept. 11, and it came up clean at that time but reappeared on Sept. 27th. I hope it doesn't reappear again, but I will keep my eye on it just in case. I don't know if anyone else has seen this thing recur, but I certainly hope not!
Thank you very much for all of your help - your service is excellent and very much appreciated!
Thank you very much for all of your help - your service is excellent and very much appreciated!
#10
Posted 28 September 2009 - 06:40 PM
Neuro,
That is that worm take care of but it was almost certainly another worm at the start of September and you/someone else has reinfected that computer.
Here's some handy reading tho Prevention page with lots of info and tips how to prevent this in the future.
And if you want to improve speed/system performance after malware removal, take a look here.
Extra note: Make sure your programs are up to date - because older versions may contain Security Leaks. To find out what programs need to be updated, please run the Secunia Software Inspector Scan.
We hope our application has helped you eradicate this malicious Malware.
If your current anti-virus solution let this infection through please consider purchasing the PRO version of Malwarebytes' Anti-Malware for additional protection against these types of malware.
Safe surfing
That is that worm take care of but it was almost certainly another worm at the start of September and you/someone else has reinfected that computer.
Here's some handy reading tho Prevention page with lots of info and tips how to prevent this in the future.
And if you want to improve speed/system performance after malware removal, take a look here.
Extra note: Make sure your programs are up to date - because older versions may contain Security Leaks. To find out what programs need to be updated, please run the Secunia Software Inspector Scan.
We hope our application has helped you eradicate this malicious Malware.
If your current anti-virus solution let this infection through please consider purchasing the PRO version of Malwarebytes' Anti-Malware for additional protection against these types of malware.
Safe surfing
1 user(s) are reading this topic
0 members, 1 guests, 0 anonymous users
Sign In
Create Account
This topic is locked
Back to top










