IAMBIGBROTHER (A) BEAST (A), NOADWARE (A), Android.Exploit.PSN.A (B), Andro

Page 1 of 2 1, 2  Next

View previous topic View next topic Go down

IAMBIGBROTHER (A) BEAST (A), NOADWARE (A), Android.Exploit.PSN.A (B), Andro

Post by cybor462 on Wed 20 Mar 2013, 10:59 pm

Hi I have been infected with a number of bad things. I have a friend who has been helping me to clean and said I should ask for help here. I have run a bunch of scanners and cleaners like AVG rescue cd, Kaspersky rescue cd, malwarebytes scanner, rkill, tdskiller, dr web rescue cd and online scanner, emsisoft scanner and now use it to guard, avast scanner and others. I was using Microsoft Security Essentials and scanned faithfully but it never caught any of these. I downloaded a database app on my smartphone and when I synced it to my pc it infected it. I am not sure if any of these were already on the pc but this is some of what the scanners reported as infected.

IAMBIGBROTHER (A) BEAST (A), NOADWARE (A), Android.Exploit.PSN.A (B), Android.Exploit.zerqrush.c (B),
These were the common ones each scanner found but every scanner found others there were so many I did not write them down.

This is the second system you guys cleaned the other. I am posting the logs

Thanks

# AdwCleaner v2.115 - Logfile created 03/19/2013 at 20:41:26
# Updated 17/03/2013 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : HP_Administrator - WORK
# Boot Mode : Normal
# Running from : C:\Documents and Settings\HP_Administrator\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****

Stopped & Deleted : VideoDownloadConverter_4zService

***** [Files / Folders] *****

File Deleted : C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\4tsctwxx.default\searchplugins\my-web-search.xml
File Deleted : C:\END
Folder Deleted : C:\Documents and Settings\All Users\Application Data\Babylon
Folder Deleted : C:\Documents and Settings\All Users\Application Data\WeCareReminder
Folder Deleted : C:\Documents and Settings\HP_Administrator\Application Data\Babylon
Folder Deleted : C:\Documents and Settings\HP_Administrator\Application Data\OpenCandy
Folder Deleted : C:\Documents and Settings\HP_Administrator\Application Data\Toolbar4
Folder Deleted : C:\Documents and Settings\HP_Administrator\Application Data\VideoDownloadConverter_4z
Folder Deleted : C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\OpenCandy
Folder Deleted : C:\Program Files\VideoDownloadConverter_4z

***** [Registry] *****

Key Deleted : HKCU\Software\Microsoft\Internet Explorer\MenuExt\&Search
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{312F84FB-8970-4FD3-BDDB-7012EAC4AFC9}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{338B4DFE-2E2C-4338-9E41-E176D497299E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C547C6C2-561B-4169-A2A5-20BA771CA93B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{201F27D4-3704-41D6-89C1-AA35E39143ED}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3041D03E-FD4B-44E0-B742-2D9B88305F98}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{312F84FB-8970-4FD3-BDDB-7012EAC4AFC9}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{338B4DFE-2E2C-4338-9E41-E176D497299E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C547C6C2-561B-4169-A2A5-20BA771CA93B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
Key Deleted : HKLM\Software\AskBarDis
Key Deleted : HKLM\Software\Babylon
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\NCTAudioCDGrabber2.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\TbCommonUtils.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\TbHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{13119113-0854-469D-807A-171568457991}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1F6F39C1-00A8-4752-A94C-D0EA92D978B6}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2A1260C1-2964-453F-B0BA-FA429472EB5F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{312F84FB-8970-4FD3-BDDB-7012EAC4AFC9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{33119133-0854-469D-807A-171568457991}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{363D5C92-10DC-4287-93E5-1832EECC48EC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B41BE90-F731-4137-AFF3-2CA951E7F0D9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4128C64D-F0DD-4811-9405-D22294E8151F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5354D921-3F52-47C5-938D-77A2FB6DEFE7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{66292684-B2C2-4C7C-B3D2-BF446E30744C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69407823-3494-4400-8D49-612549E8F4EE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6BFF4BCB-7A73-45A7-AC4C-389A34E1D1EF}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{71144427-1368-4D18-8DC9-2AE3CC4C4F83}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8FCA5302-6D6D-4645-BF99-D43CF76CE474}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{99E1F6FD-2E94-4CF6-8344-1BA63CD3BD9B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C547C6C2-561B-4169-A2A5-20BA771CA93B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DD385519-22E7-4BE2-8A8D-35C66DF4858E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ED345812-2722-4DCA-9976-D01832DB44EE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Classes\IMsiDe1egate.Application.1
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{17B10E59-09E1-4C39-A738-6774D7AB7778}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD2049E-E483-4425-8555-8E0775ACB631}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2D73F2D0-2FAB-458E-977D-2F9050E0ED60}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3E9469AF-E866-4476-B767-810630F1F6E7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{47700C35-9E3E-4DAD-934C-0CE28A87237C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{49C00A51-6E59-41FE-B3FA-2D2157FAD67B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6DFF5DBA-AE3A-46DB-B301-ECFFC6DB2982}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{716E443D-7CAA-44F1-866B-F45D00E712CC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{72063D77-7590-4DA9-A7F8-F5ECAF3632C4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7FC87AC5-FA93-476E-A32C-A941229DED0B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DE34CD67-F1C8-4001-9A23-B8A68F63F377}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils
Key Deleted : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils.1
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager.1
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager.1
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbRequest
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbRequest.1
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbTask
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbTask.1
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper.1
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{03119103-0854-469D-807A-171568457991}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2D3826A1-F3E8-45D6-94B5-C26D8EC0073B}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{3EE17DD1-E28B-4AED-A3B2-9C29CB2C19D6}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{886F93AD-3CBB-4424-8442-A7340243540F}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{AA289DBC-59B6-40A5-AC7D-C90DF850289C}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B87F8B63-7274-43FD-87FA-09D3B7496148}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C4BAE205-5E02-4E32-876E-F34B4E2D000C}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{CA723163-6FAD-43D4-8B93-0D8C52BD9974}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{F1F328EB-F5A5-432B-A54C-05F3EF5B0BD8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{FB0E8A09-F08C-44CF-9E15-97ADAC016248}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{FE8DBB09-C3D3-4477-80CB-D38914B94BB8}
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.DynamicBarButton
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.DynamicBarButton.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.FeedManager
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.FeedManager.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.HTMLMenu
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.HTMLMenu.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.HTMLPanel
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.HTMLPanel.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.MultipleButton
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.MultipleButton.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.PseudoTransparentPlugin
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.PseudoTransparentPlugin.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.Radio
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.Radio.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.RadioSettings
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.RadioSettings.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ScriptButton
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ScriptButton.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.SettingsPlugin
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.SettingsPlugin.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.SkinLauncher
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.SkinLauncher.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ThirdPartyInstaller
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.ThirdPartyInstaller.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.UrlAlertButton
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.UrlAlertButton.1
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.XMLSessionPlugin
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter_4z.XMLSessionPlugin.1
Key Deleted : HKLM\Software\Freeze.com
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\VideoDownloadConverter_4zbar Uninstall
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{312F84FB-8970-4FD3-BDDB-7012EAC4AFC9}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C547C6C2-561B-4169-A2A5-20BA771CA93B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1F6F39C1-00A8-4752-A94C-D0EA92D978B6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5354D921-3F52-47C5-938D-77A2FB6DEFE7}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{71144427-1368-4D18-8DC9-2AE3CC4C4F83}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{99E1F6FD-2E94-4CF6-8344-1BA63CD3BD9B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{ED345812-2722-4DCA-9976-D01832DB44EE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VideoDownloadConverter_4zbar Uninstall
Key Deleted : HKLM\Software\TENCENT
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{93A3111F-4F74-4ED8-895E-D9708497629E}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [VideoDownloadConverter Search Scope Monitor]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [VideoDownloadConverter_4z Browser Plugin Loader]

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = [You must be registered and logged in to see this link.] --> [You must be registered and logged in to see this link.]

-\\ Mozilla Firefox v19.0 (en-US)

File : C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\4tsctwxx.default\prefs.js

C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\4tsctwxx.default\user.js ... Deleted !

Deleted : user_pref("browser.search.defaultenginename", "My Web Search");
Deleted : user_pref("extensions.mywebsearch.prevDefaultEngine", "Google");
Deleted : user_pref("extensions.mywebsearch.prevKwdEnabled", true);
Deleted : user_pref("extensions.mywebsearch.prevKwdURL", "hxxp://search.mywebsearch.com/mywebsearch/GGmain.jht[...]
Deleted : user_pref("extensions.mywebsearch.prevSelectedEngine", "Google");
Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.homepage", "hxxp://home.mywebsearch.com/index.jh[...]
Deleted : user_pref("keyword.URL", "hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?st=kwd&ptb=15BE877B[...]

-\\ Google Chrome v [Unable to get version]

File : C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

-\\ Opera v12.14.1738.0

File : C:\Documents and Settings\HP_Administrator\Application Data\Opera\Opera\operaprefs.ini

[OK] File is clean.

*************************

AdwCleaner[S1].txt - [15326 octets] - [19/03/2013 20:41:26]

########## EOF - C:\AdwCleaner[S1].txt - [15387 octets] ##########



cybor462

Newbie Surfer
Newbie Surfer

Posts : 42
Joined : 2013-03-17
Operating System : XP

View user profile

Back to top Go down

Re: IAMBIGBROTHER (A) BEAST (A), NOADWARE (A), Android.Exploit.PSN.A (B), Andro

Post by cybor462 on Wed 20 Mar 2013, 11:00 pm

Malwarebytes Anti-Malware 1.70.0.1100
[You must be registered and logged in to see this link.]

Database version: v2013.03.19.10

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
HP_Administrator :: WORK [administrator]

3/19/2013 9:04:14 PM
mbam-log-2013-03-19 (21-04-14).txt

Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 644966
Time elapsed: 6 hour(s), 26 minute(s), 53 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)


cybor462

Newbie Surfer
Newbie Surfer

Posts : 42
Joined : 2013-03-17
Operating System : XP

View user profile

Back to top Go down

Re: IAMBIGBROTHER (A) BEAST (A), NOADWARE (A), Android.Exploit.PSN.A (B), Andro

Post by cybor462 on Wed 20 Mar 2013, 11:01 pm

Results of screen317's Security Check version 0.99.61
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Microsoft Security Essentials
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Out of date HijackThis installed!
Malwarebytes Anti-Malware version 1.70.0.1100
HijackThis 2.0.2
CCleaner
Java 7 Update 17
Adobe Flash Player 11.6.602.180
Adobe Reader 9 Adobe Reader out of Date!
Adobe Reader 10.1.6 Adobe Reader out of Date!
Mozilla Firefox (19.0)
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 4%
````````````````````End of Log``````````````````````


cybor462

Newbie Surfer
Newbie Surfer

Posts : 42
Joined : 2013-03-17
Operating System : XP

View user profile

Back to top Go down

Re: IAMBIGBROTHER (A) BEAST (A), NOADWARE (A), Android.Exploit.PSN.A (B), Andro

Post by cybor462 on Wed 20 Mar 2013, 11:02 pm

These are the logs so far
Thanks

cybor462

Newbie Surfer
Newbie Surfer

Posts : 42
Joined : 2013-03-17
Operating System : XP

View user profile

Back to top Go down

Re: IAMBIGBROTHER (A) BEAST (A), NOADWARE (A), Android.Exploit.PSN.A (B), Andro

Post by Superdave on Thu 21 Mar 2013, 10:42 am

Download Combofix from any of the links below, and save it to your DESKTOP.
If your version of Windows defaults to you download folder you will need to copy it to your desktop.

Link 1
Link 2
Link 3

To prevent your anti-virus application interfering with ComboFix we need to disable it. See here for a tutorial regarding how to do so if you are unsure.

  • Close any open windows and double click ComboFix.exe to run it.

    You will see the following image:



Click I Agree to start the program.

ComboFix will then extract the necessary files and you will see this:



As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. This will not occur in Windows Vista and 7

It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

If you did not have it installed, you will see the prompt below. Choose YES.



Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



Click on Yes, to continue scanning for malware.

When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).

Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do so.

Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.

Superdave
Tech Staff


Tech Staff

Posts : 4193
Joined : 2010-02-01
Operating System : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: IAMBIGBROTHER (A) BEAST (A), NOADWARE (A), Android.Exploit.PSN.A (B), Andro

Post by cybor462 on Thu 21 Mar 2013, 11:51 am

combofix crashed and I had to restart what now

I tried to run again not sure if it is working been awhile and its still has the open window

Seems like it is stalled It has been running for hours and still says scanning for infected files. I m shutting it down until I hear from you to see what to try next.

cybor462

Newbie Surfer
Newbie Surfer

Posts : 42
Joined : 2013-03-17
Operating System : XP

View user profile

Back to top Go down

Re: IAMBIGBROTHER (A) BEAST (A), NOADWARE (A), Android.Exploit.PSN.A (B), Andro

Post by Superdave on Fri 22 Mar 2013, 9:43 am

Please try running it in Safe Mode.

Superdave
Tech Staff


Tech Staff

Posts : 4193
Joined : 2010-02-01
Operating System : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: IAMBIGBROTHER (A) BEAST (A), NOADWARE (A), Android.Exploit.PSN.A (B), Andro

Post by cybor462 on Fri 22 Mar 2013, 11:58 am

trying it now

did the same thing in safe mode just crashed the machine and I had to force shut down

cybor462

Newbie Surfer
Newbie Surfer

Posts : 42
Joined : 2013-03-17
Operating System : XP

View user profile

Back to top Go down

Re: IAMBIGBROTHER (A) BEAST (A), NOADWARE (A), Android.Exploit.PSN.A (B), Andro

Post by cybor462 on Sat 23 Mar 2013, 3:44 pm



Combofix not working in normal or safe mode what should I try next

Thanks

cybor462

Newbie Surfer
Newbie Surfer

Posts : 42
Joined : 2013-03-17
Operating System : XP

View user profile

Back to top Go down

Re: IAMBIGBROTHER (A) BEAST (A), NOADWARE (A), Android.Exploit.PSN.A (B), Andro

Post by Superdave on Sun 24 Mar 2013, 9:38 am

This is the same program but you will need to rename it.

Download Combofix from any of the links below, and save it to your DESKTOP.
If your version of Windows defaults to your download folder, you will need to copy it to your desktop.

Link 1
Link 2
Link 3

When saving ComboFix rename it to PCHelpForum.exe to prevent it from being blocked by malware.

To prevent your anti-virus application interfering with ComboFix we need to disable it. See here for a tutorial regarding how to do so if you are unsure.

  • Close any open windows and double click PCHelpForum.exe to run it.

    You will see the following image:



Click I Agree to start the program.

ComboFix will then extract the necessary files and you will see this:



As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. This will not occur in Windows Vista and 7

It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

If you did not have it installed, you will see the prompt below. Choose YES.



Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



Click on Yes, to continue scanning for malware.

When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).

Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do so.

Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.
*************************************

  • Download RogueKiller on the desktop
  • Close all the running programs
  • Windows Vista/7 users: right click on RogueKiller.exe, click Run as Administrator
  • Otherwise just double-click on RogueKiller.exe
  • Pre-scan will start. Let it finish.
  • Click on SCAN button.
  • A report (RKreport.txt) should open. Post its content in your next reply. (RKreport could also be found on your desktop)
  • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again


Superdave
Tech Staff


Tech Staff

Posts : 4193
Joined : 2010-02-01
Operating System : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: IAMBIGBROTHER (A) BEAST (A), NOADWARE (A), Android.Exploit.PSN.A (B), Andro

Post by cybor462 on Sun 24 Mar 2013, 9:43 am

ok doing it now thanks

doing the same thing it just freezes the system both normal and safe mode

cybor462

Newbie Surfer
Newbie Surfer

Posts : 42
Joined : 2013-03-17
Operating System : XP

View user profile

Back to top Go down

Re: IAMBIGBROTHER (A) BEAST (A), NOADWARE (A), Android.Exploit.PSN.A (B), Andro

Post by Superdave on Mon 25 Mar 2013, 12:16 pm

cybor462 wrote:ok doing it now thanks

doing the same thing it just freezes the system both normal and safe mode
Ok, please run the RogueKiller scan and post the log.

Superdave
Tech Staff


Tech Staff

Posts : 4193
Joined : 2010-02-01
Operating System : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: IAMBIGBROTHER (A) BEAST (A), NOADWARE (A), Android.Exploit.PSN.A (B), Andro

Post by cybor462 on Mon 25 Mar 2013, 12:32 pm

Rkiller ran found something but did not write a log. I cant find it anyway. It only put a folder on the desktop with a EULA.txt which is the license agreement

cybor462

Newbie Surfer
Newbie Surfer

Posts : 42
Joined : 2013-03-17
Operating System : XP

View user profile

Back to top Go down

Re: IAMBIGBROTHER (A) BEAST (A), NOADWARE (A), Android.Exploit.PSN.A (B), Andro

Post by Superdave on Mon 25 Mar 2013, 12:50 pm

I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan

•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.

•Check
•Click the button.
•Accept any security warnings from your browser.

  • Leave the check mark next to Remove found threats.

•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

Superdave
Tech Staff


Tech Staff

Posts : 4193
Joined : 2010-02-01
Operating System : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: IAMBIGBROTHER (A) BEAST (A), NOADWARE (A), Android.Exploit.PSN.A (B), Andro

Post by cybor462 on Mon 25 Mar 2013, 1:26 pm

doing it now

cybor462

Newbie Surfer
Newbie Surfer

Posts : 42
Joined : 2013-03-17
Operating System : XP

View user profile

Back to top Go down

Re: IAMBIGBROTHER (A) BEAST (A), NOADWARE (A), Android.Exploit.PSN.A (B), Andro

Post by cybor462 on Mon 25 Mar 2013, 5:40 pm

C:\Documents and Settings\HP_Administrator\My Documents\samsung files sd card\App_Manager\App_Backups\user_apps\com.charmingapps.rebelflag.apk a variant of Android/Adware.AirPush.G application deleted - quarantined
C:\Documents and Settings\HP_Administrator\My Documents\samsung files sd card\TitaniumBackup\com.charmingapps.rebelflag-2e43b4cc0c66b79c382df1a4044e5191.apk.gz a variant of Android/Adware.AirPush.G application deleted - quarantined
C:\Documents and Settings\HP_Administrator\My Documents\samsung files sd card\TitaniumBackup\com.charmingapps.rebelflag-ec930064db8a53503f88c34c285a17ba.apk.gz a variant of Android/Adware.AirPush.G application deleted - quarantined


cybor462

Newbie Surfer
Newbie Surfer

Posts : 42
Joined : 2013-03-17
Operating System : XP

View user profile

Back to top Go down

Re: IAMBIGBROTHER (A) BEAST (A), NOADWARE (A), Android.Exploit.PSN.A (B), Andro

Post by Superdave on Tue 26 Mar 2013, 6:21 am

That looks good. How's your computer running now?

Superdave
Tech Staff


Tech Staff

Posts : 4193
Joined : 2010-02-01
Operating System : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: IAMBIGBROTHER (A) BEAST (A), NOADWARE (A), Android.Exploit.PSN.A (B), Andro

Post by cybor462 on Tue 26 Mar 2013, 7:04 am

seems ok do you think its clean?

The other pc that we worked on seemed ok but fell apart soon after found more bugs and its a mess. The firewall takes 5 min to start and AV will not start so I cant go online. Services are flaky unable to start or stop anything just keeps crashing the system. Something on that one seems to be keeping the services from working correctly and keeps system restore, firewall and security center from starting for 5-10 minutes then they pop up.
Are we sure this is clean? If so can we look at the other again? or do you have any other suggestions.
Thanks

cybor462

Newbie Surfer
Newbie Surfer

Posts : 42
Joined : 2013-03-17
Operating System : XP

View user profile

Back to top Go down

Re: IAMBIGBROTHER (A) BEAST (A), NOADWARE (A), Android.Exploit.PSN.A (B), Andro

Post by cybor462 on Tue 26 Mar 2013, 7:09 am

Well I lied I checked the firewall and AV and they both were running as reported by security center but now the firewall reports to be turned off and I checked it with netsh and it says the service is not started This is on the pc we just scanned. I cant turn the firewall on manually or in security center says AVG firewall is reporting its turned off but as far as I know I dont have AVG had it a year
ago but uninstalled it when I started MSE

cybor462

Newbie Surfer
Newbie Surfer

Posts : 42
Joined : 2013-03-17
Operating System : XP

View user profile

Back to top Go down

Re: IAMBIGBROTHER (A) BEAST (A), NOADWARE (A), Android.Exploit.PSN.A (B), Andro

Post by Superdave on Tue 26 Mar 2013, 9:25 am

cybor462 wrote:Well I lied I checked the firewall and AV and they both were running as reported by security center but now the firewall reports to be turned off and I checked it with netsh and it says the service is not started This is on the pc we just scanned. I cant turn the firewall on manually or in security center says AVG firewall is reporting its turned off but as far as I know I dont have AVG had it a year
ago but uninstalled it when I started MSE
Now I'm confused. Which computer are we talking about now?

Superdave
Tech Staff


Tech Staff

Posts : 4193
Joined : 2010-02-01
Operating System : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: IAMBIGBROTHER (A) BEAST (A), NOADWARE (A), Android.Exploit.PSN.A (B), Andro

Post by cybor462 on Tue 26 Mar 2013, 10:00 am

This post is about the pc we just scanned. I have an update...... when I uninstalled MSE the firewall turned on and stays on and does this with every reboot. I will try another AV and see if it works.

Well I lied I checked the firewall and AV and they both were running as reported by security center but now the firewall reports to be turned off and I checked it with netsh and it says the service is not started This is on the pc we just scanned. I cant turn the firewall on manually or in security center says AVG firewall is reporting its turned off but as far as I know I dont have AVG had it a year ago but uninstalled it when I started using MSE



This post is concerning the pc you helped me with last week. they have the same OS (XP) but are in different computers.

The other pc that we worked on seemed ok but fell apart soon after found more bugs and its a mess. The firewall takes 5 min to start and AV will not start so I cant go online. Services are flaky unable to start or stop anything just keeps crashing the system. Something on that one seems to be keeping the services from working correctly and keeps system restore, firewall and security center from starting for 5-10 minutes then they pop up.
Are we sure this is clean? If so can we look at the other again? or do you have any other suggestions.
Thanks

cybor462

Newbie Surfer
Newbie Surfer

Posts : 42
Joined : 2013-03-17
Operating System : XP

View user profile

Back to top Go down

Re: IAMBIGBROTHER (A) BEAST (A), NOADWARE (A), Android.Exploit.PSN.A (B), Andro

Post by Superdave on Tue 26 Mar 2013, 12:52 pm

Ok. Let's do some cleanup and see what happens.

To turn off Windows XP System Restore:

NOTE: These instructions assume that you are using the default Windows XP Start Menu and have not changed to the Classic Start menu. To re-enable the default menu, right-click Start, click Properties, click Start menu (not Classic) and then click OK.

1. Click Start.
2. Right-click the My Computer icon, and then click Properties.
3. Click the System Restore tab.
4. Check "Turn off System Restore" or "Turn off System Restore on all drives"
5. Click Apply.
6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
7. Click OK.
8. Restart the computer and follow the instructions in the next section to turn on System Restore.

To turn on Windows XP System Restore:

1. Click Start.
2. Right-click My Computer, and then click Properties.
3. Click the System Restore tab.
4. Uncheck "Turn off System Restore" or "Turn off System Restore on all drives."
5. Click Apply, and then click OK.
********************************************
Click Start> Computer> right click the C Drive and choose Properties> enter
Click Disk Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.



This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
**************************************
Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!

Superdave
Tech Staff


Tech Staff

Posts : 4193
Joined : 2010-02-01
Operating System : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: IAMBIGBROTHER (A) BEAST (A), NOADWARE (A), Android.Exploit.PSN.A (B), Andro

Post by cybor462 on Tue 26 Mar 2013, 1:19 pm

ran uninstall on combofix and the others and now I cant get to system restore to do this last cleanup.

I have an image of it before the uninstall was done so I will restore it and then wait for your help getting them off without screwing it up

cybor462

Newbie Surfer
Newbie Surfer

Posts : 42
Joined : 2013-03-17
Operating System : XP

View user profile

Back to top Go down

Re: IAMBIGBROTHER (A) BEAST (A), NOADWARE (A), Android.Exploit.PSN.A (B), Andro

Post by Superdave on Wed 27 Mar 2013, 4:50 am

cybor462 wrote:ran uninstall on combofix and the others and now I cant get to system restore to do this last cleanup.
I have an image of it before the uninstall was done so I will restore it and then wait for your help getting them off without screwing it up
I'm not sure I understand but the proper removal of ComboFix removes all your previous Restore Points and creates a new one. This is to eliminate any infection hiding in System Restore.

Superdave
Tech Staff


Tech Staff

Posts : 4193
Joined : 2010-02-01
Operating System : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: IAMBIGBROTHER (A) BEAST (A), NOADWARE (A), Android.Exploit.PSN.A (B), Andro

Post by cybor462 on Wed 27 Mar 2013, 4:58 am

Not sure but since we finished with it System restore does not work nor does security center. If I uninstall the AV then security center works and firewall turns on. If AV is installed I tried several now if AV is installed firewall turns off and cant be started and security center and system restore do not work. if AV is uninstalled firewall is on and security center works and system restore works. I am lost here

cybor462

Newbie Surfer
Newbie Surfer

Posts : 42
Joined : 2013-03-17
Operating System : XP

View user profile

Back to top Go down

Re: IAMBIGBROTHER (A) BEAST (A), NOADWARE (A), Android.Exploit.PSN.A (B), Andro

Post by Sponsored content Today at 9:21 am


Sponsored content


Back to top Go down

Page 1 of 2 1, 2  Next

View previous topic View next topic Back to top


 
Permissions in this forum:
You cannot reply to topics in this forum