djarvis1one
New Member
I received a panic call from my son while I was working this evening. He has a:
Toshiba Satellite L305-S5895 laptop
AMD Turion 64X2 TL-60 / 2.0 Ghz dual core Amd M690G chipset
3 GB DDR2 SDRAM 667.0 Mhz PC2 - 5300 (1x1GB + 1x2GB)
250 GB WD 5400rpm HDD
ATI Radeon X1250 GPU
On startup a dialog box opened stating that Windows Live A/V had found a worm
(he is running Avira A/V and Malwarebytes and we left Windows Defender on plus the standard Windows firewall) so I don't know where the Live A/V came from. After machine booted completely, I ran Malwarebytes and OMG the shit hit the fan.
Here is he first log:
Malwarebytes' Anti-Malware 1.41
Database version: 3284
Windows 6.0.6002 Service Pack 2
12/17/2009 10:52:58 PM
mbam-log-2009-12-17 (22-52-42).txt
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 216780
Time elapsed: 48 minute(s), 33 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 5
Registry Data Items Infected: 5
Folders Infected: 0
Files Infected: 10
Memory Processes Infected:
C:\Users\justin\AppData\Local\emckir\uqfbsysguard.exe (Spyware.Passwords) -> No action taken.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{a5bf49a2-94f1-42bd-f434-3604812c807d} (Trojan.Zlob.H) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\AvScan (Trojan.FakeAlert) -> No action taken.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{a5bf49a2-94f1-42bd-f434-3604812c807d} (Trojan.Zlob.H) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\alobrvgh (Spyware.Passwords) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\idstrf (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\WINID (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\asg984jgkfmgasi8ug98jgkfgfb (Trojan.Downloader) -> No action taken.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: c:\windows\system32\winlogon86.exe -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: system32\winlogon86.exe -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\Windows\system32\winlogon86.exe) Good: (Userinit.exe) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> No action taken.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Windows\System32\rtweiyu.dll (Trojan.Zlob.H) -> No action taken.
C:\Users\justin\AppData\Local\emckir\uqfbsysguard.exe (Spyware.Passwords) -> No action taken.
C:\Users\justin\AppData\Local\Temp\7bfe9b19.exe (Spyware.Passwords) -> No action taken.
C:\Users\justin\AppData\Local\Temp\taskmgr.exe (Trojan.Downloader) -> No action taken.
C:\Users\justin\AppData\Local\Temp\jisfije9fjoiee.tmp (Trojan.Downloader) -> No action taken.
C:\Users\justin\AppData\Local\Temp\debug.exe (Trojan.Downloader) -> No action taken.
C:\Windows\System32\AVR10.exe (Trojan.FakeAlert) -> No action taken.
C:\Windows\System32\winhelper86.dll (Trojan.FakeAlert) -> No action taken.
C:\Windows\System32\41.exe (Trojan.FakeAlert) -> No action taken.
C:\Windows\System32\Winlogon86.exe (Trojan.FakeAlert) -> No action taken.
I clicked on the remove tab and ran another quick scan and came up with this:
Malwarebytes' Anti-Malware 1.42
Database version: 3383
Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005
12/17/2009 11:34:06 PM
mbam-log-2009-12-17 (23-34-06).txt
Scan type: Quick Scan
Objects scanned: 94979
Time elapsed: 4 minute(s), 0 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 7
Memory Processes Infected:
C:\Users\justin\AppData\Local\Temp\o08vm063d.exe (Trojan.Downloader) -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a5bf49a2-94f1-42bd-f434-3604812c807d} (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a5bf49a2-94f1-42bd-f434-3604812c807d} (Trojan.Downloader) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ygua8e7yhuiesfha876yfauy8fe (Trojan.Downloader) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Users\justin\AppData\Local\Temp\o08vm063d.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\system32\Drivers\byvqav.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Users\justin\AppData\Local\Temp\1104593601.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\justin\AppData\Local\Temp\2417000672.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\justin\AppData\Local\Temp\o7txlnw9.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\justin\AppData\Local\Temp\install.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\justin\AppData\Local\Temp\winamp.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
It was at this scan that I realized that MB was out of date, so I updated and it is currently in the process of scanning.
I will repost the newest scan tomorrow. Any insight in the meantime will be greatly appreciated!!
Toshiba Satellite L305-S5895 laptop
AMD Turion 64X2 TL-60 / 2.0 Ghz dual core Amd M690G chipset
3 GB DDR2 SDRAM 667.0 Mhz PC2 - 5300 (1x1GB + 1x2GB)
250 GB WD 5400rpm HDD
ATI Radeon X1250 GPU
On startup a dialog box opened stating that Windows Live A/V had found a worm
(he is running Avira A/V and Malwarebytes and we left Windows Defender on plus the standard Windows firewall) so I don't know where the Live A/V came from. After machine booted completely, I ran Malwarebytes and OMG the shit hit the fan.
Here is he first log:
Malwarebytes' Anti-Malware 1.41
Database version: 3284
Windows 6.0.6002 Service Pack 2
12/17/2009 10:52:58 PM
mbam-log-2009-12-17 (22-52-42).txt
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 216780
Time elapsed: 48 minute(s), 33 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 5
Registry Data Items Infected: 5
Folders Infected: 0
Files Infected: 10
Memory Processes Infected:
C:\Users\justin\AppData\Local\emckir\uqfbsysguard.exe (Spyware.Passwords) -> No action taken.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{a5bf49a2-94f1-42bd-f434-3604812c807d} (Trojan.Zlob.H) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\AvScan (Trojan.FakeAlert) -> No action taken.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{a5bf49a2-94f1-42bd-f434-3604812c807d} (Trojan.Zlob.H) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\alobrvgh (Spyware.Passwords) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\idstrf (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\WINID (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\asg984jgkfmgasi8ug98jgkfgfb (Trojan.Downloader) -> No action taken.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: c:\windows\system32\winlogon86.exe -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: system32\winlogon86.exe -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\Windows\system32\winlogon86.exe) Good: (Userinit.exe) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> No action taken.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Windows\System32\rtweiyu.dll (Trojan.Zlob.H) -> No action taken.
C:\Users\justin\AppData\Local\emckir\uqfbsysguard.exe (Spyware.Passwords) -> No action taken.
C:\Users\justin\AppData\Local\Temp\7bfe9b19.exe (Spyware.Passwords) -> No action taken.
C:\Users\justin\AppData\Local\Temp\taskmgr.exe (Trojan.Downloader) -> No action taken.
C:\Users\justin\AppData\Local\Temp\jisfije9fjoiee.tmp (Trojan.Downloader) -> No action taken.
C:\Users\justin\AppData\Local\Temp\debug.exe (Trojan.Downloader) -> No action taken.
C:\Windows\System32\AVR10.exe (Trojan.FakeAlert) -> No action taken.
C:\Windows\System32\winhelper86.dll (Trojan.FakeAlert) -> No action taken.
C:\Windows\System32\41.exe (Trojan.FakeAlert) -> No action taken.
C:\Windows\System32\Winlogon86.exe (Trojan.FakeAlert) -> No action taken.
I clicked on the remove tab and ran another quick scan and came up with this:
Malwarebytes' Anti-Malware 1.42
Database version: 3383
Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005
12/17/2009 11:34:06 PM
mbam-log-2009-12-17 (23-34-06).txt
Scan type: Quick Scan
Objects scanned: 94979
Time elapsed: 4 minute(s), 0 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 7
Memory Processes Infected:
C:\Users\justin\AppData\Local\Temp\o08vm063d.exe (Trojan.Downloader) -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a5bf49a2-94f1-42bd-f434-3604812c807d} (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a5bf49a2-94f1-42bd-f434-3604812c807d} (Trojan.Downloader) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ygua8e7yhuiesfha876yfauy8fe (Trojan.Downloader) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Users\justin\AppData\Local\Temp\o08vm063d.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\system32\Drivers\byvqav.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Users\justin\AppData\Local\Temp\1104593601.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\justin\AppData\Local\Temp\2417000672.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\justin\AppData\Local\Temp\o7txlnw9.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\justin\AppData\Local\Temp\install.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\justin\AppData\Local\Temp\winamp.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
It was at this scan that I realized that MB was out of date, so I updated and it is currently in the process of scanning.
I will repost the newest scan tomorrow. Any insight in the meantime will be greatly appreciated!!