Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Bug screensaver virus  (Read 29778 times)

0 Members and 1 Guest are viewing this topic.

lufo4

    Topic Starter


    Rookie

    Re: Bug screensaver virus
    « Reply #30 on: May 11, 2008, 11:59:06 AM »
    the log is too large for a single post
    here is part 1


    _______________________________________ _____

    Malwarebytes' Anti-Malware 1.12
    Database version: 722

    Scan type: Full Scan (C:\|E:\|)
    Objects scanned: 407932
    Time elapsed: 2 hour(s), 43 minute(s), 22 second(s)

    Memory Processes Infected: 1
    Memory Modules Infected: 5
    Registry Keys Infected: 49
    Registry Values Infected: 14
    Registry Data Items Infected: 0
    Folders Infected: 45
    Files Infected: 155

    Memory Processes Infected:
    e:\WINDOWS\system32\drivers\spools.exe (Worm.Socks) -> Unloaded process successfully.

    Memory Modules Infected:
    e:\WINDOWS\system32\crypts.dll (Trojan.Downloader) -> Unloaded module successfully.
    E:\WINDOWS\system32\hdxjd4g.dll (Trojan.Agent) -> Unloaded module successfully.
    E:\WINDOWS\system32\djki397g.dll (Trojan.Agent) -> Unloaded module successfully.
    E:\WINDOWS\system32\__c0022FF9.dat (Trojan.Agent) -> Unloaded module successfully.
    E:\WINDOWS\system32\basenpnv32.dll (Trojan.Downloader) -> Unloaded module successfully.

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\schedule (Worm.Socks) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\schedule (Worm.Socks) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\schedule (Worm.Socks) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\schedule (Worm.Socks) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{B5AC49A2-94F2-42BD-F434-2604812C897D} (Trojan.Zlob) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{B5AF0562-94F3-42BD-F434-2604812C797D} (Trojan.Zlob) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{e4e3e0f8-cd30-4380-8ce9-b96904bdefca} (Adware.PopCap) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{fe8a736f-4124-4d9c-b4b1-3b12381efabe} (Adware.PopCap) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Typelib\{c9c5deaf-0a1f-4660-8279-9edfad6fefe1} (Adware.PopCap) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{f2f2a4cb-daad-4d0c-bdfc-e945647202c2} (Trojan.BHO) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b5ac49a2-94f2-42bd-f434-2604812c897d} (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b5af0562-94f3-42bd-f434-2604812c797d} (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{43382522-a846-46f4-ac57-1f71ae6e1086} (Adware.WhenUSave) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{572fb162-c0ba-4edf-8cff-e3846153b9b0} (Adware.WhenUSave) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{72a836d1-bc00-43c0-a941-17960e4fb842} (Adware.WhenUSave) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cjp74 (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\cjp74 (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\cjp74 (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cjp74 (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\starware337 (Adware.Starware) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\qandr (Rootkit.Agent) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\qandr (Rootkit.Agent) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\qandr (Rootkit.Agent) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Google Online Services (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c0022ff9 (Trojan.Agent) -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\Software\Microsoft\aldd (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\Software\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\Software\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\Software\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\Software\Starware337 (Adware.Starware) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ntuser (Worm.Socks) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ntuser (Worm.Socks) -> Quarantined and deleted successfully.
    HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ntuser (Worm.Socks) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{B5AC49A2-94F2-42BD-F434-2604812C897D} (Trojan.Zlob) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{B5AF0562-94F3-42BD-F434-2604812C797D} (Trojan.Zlob) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\autoload (Worm.Socks) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\autoload (Worm.Socks) -> Quarantined and deleted successfully.
    HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\autoload (Worm.Socks) -> Quarantined and deleted successfully.
    HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Jnskdfmf9eldfd (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Hhjg5jfd93dftdf (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07aa283a-43d7-4cbe-a064-32a21112d94d} (Adware.Zango) -> Quarantined and deleted successfully.
    HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\kavir (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\windows update loader (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&Search\ (Adware.Hotbar) -> Quarantined and deleted successfully.

    _______________________________________ _______________________


    lufo4

      Topic Starter


      Rookie

      Re: Bug screensaver virus
      « Reply #31 on: May 11, 2008, 12:01:05 PM »
      here is part 2

      _______________________________________ _________________________
      Registry Data Items Infected:
      (No malicious items detected)

      Folders Infected:
      E:\Program Files\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      E:\Program Files\MyWebSearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      E:\Program Files\MyWebSearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      E:\Program Files\MyWebSearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      E:\Program Files\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      E:\Program Files\FunWebProducts\ScreenSaver (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      E:\Program Files\FunWebProducts\Shared (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      E:\Program Files\FunWebProducts\ScreenSaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      E:\Program Files\Starware337 (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Program Files\Starware337\bin (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Program Files\Starware337\icons (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\All Users\Application Data\Starware337 (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\All Users\Application Data\Starware337\buttons (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\All Users\Application Data\Starware337\contexts (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\All Users\Application Data\Starware337\images (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\All Users\Application Data\Starware337\SimpleUpdate (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\jupiter\Application Data\Starware337 (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\jupiter\Application Data\Starware337\BrowserSearch (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\jupiter\Application Data\Starware337\ErrorSearch (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\jupiter\Application Data\Starware337\Games (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\jupiter\Application Data\Starware337\Layouts (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\jupiter\Application Data\Starware337\Manager (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\jupiter\Application Data\Starware337\Movies (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\jupiter\Application Data\Starware337\Recipes (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\jupiter\Application Data\Starware337\RecipeSearch (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\jupiter\Application Data\Starware337\Reference (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\jupiter\Application Data\Starware337\RelatedSearch (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\jupiter\Application Data\Starware337\ScreensaversMarketingSitePager (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\jupiter\Application Data\Starware337\SearchAssistPlus (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\jupiter\Application Data\Starware337\SearchMatch (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\jupiter\Application Data\Starware337\Toolbar (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\jupiter\Application Data\Starware337\ToolbarLogo (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\jupiter\Application Data\Starware337\ToolbarSearch (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\jupiter\Application Data\Starware337\TravelSearch (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\jupiter\Application Data\Starware337\Weather (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\jupiter\Application Data\Starware337\Games\images (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\jupiter\Application Data\Starware337\Games\images\active (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\jupiter\Application Data\Starware337\Games\images\default (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\jupiter\Application Data\Starware337\Movies\images (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\jupiter\Application Data\Starware337\Movies\images\active (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\jupiter\Application Data\Starware337\Movies\images\default (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\jupiter\Application Data\Starware337\ScreensaversMarketingSitePager\images (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\jupiter\Application Data\Starware337\ScreensaversMarketingSitePager\images\active (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\jupiter\Application Data\Starware337\ScreensaversMarketingSitePager\images\default (Adware.Starware) -> Quarantined and deleted successfully.
      E:\Documents and Settings\jupiter\Application Data\Starware337\SearchMatch\searchMatchPages (Adware.Starware) -> Quarantined and deleted successfully.

      part 3 comes next

      _______________________________________ __________________


      lufo4

        Topic Starter


        Rookie

        Re: Bug screensaver virus
        « Reply #32 on: May 11, 2008, 12:02:19 PM »
        her is part 3

        _______________________________________ _______

        Files Infected:
        e:\WINDOWS\system32\crypts.dll (Trojan.Downloader) -> Delete on reboot.
        e:\WINDOWS\system32\drivers\spools.exe (Worm.Socks) -> Quarantined and deleted successfully.
        E:\WINDOWS\system32\hdxjd4g.dll (Trojan.Zlob) -> Delete on reboot.
        E:\WINDOWS\system32\djki397g.dll (Trojan.Zlob) -> Delete on reboot.
        E:\Documents and Settings\jupiter\cftmon.exe (Worm.Socks) -> Quarantined and deleted successfully.
        E:\Documents and Settings\LocalService\cftmon.exe (Worm.Socks) -> Quarantined and deleted successfully.
        E:\WINDOWS\Temp\csrssc.exe (Trojan.Agent) -> Quarantined and deleted successfully.
        E:\WINDOWS\Temp\winlagon.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        c:\autoex.dll (Trojan.BHO) -> Quarantined and deleted successfully.
        C:\everything else like windows stuff\New Folder\Setup.exe (Adware.Zango) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Local Settings\Temp\2839312628.exe (Trojan.Agent) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Local Settings\Temp\749B.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Local Settings\Temp\csrssc.exe (Trojan.Agent) -> Quarantined and deleted successfully.
        E:\Program Files\HP Games\Star Defender 4\sqlite3.dll (Rogue.Multiple) -> Quarantined and deleted successfully.
        E:\System Volume Information\_restore{F32A7D6C-7F82-4E40-82A8-63C3A783E380}\RP2\A0000014.exe (Worm.Socks) -> Quarantined and deleted successfully.
        E:\System Volume Information\_restore{F32A7D6C-7F82-4E40-82A8-63C3A783E380}\RP4\A0000077.sys (Trojan.Downloader) -> Quarantined and deleted successfully.
        E:\System Volume Information\_restore{F32A7D6C-7F82-4E40-82A8-63C3A783E380}\RP4\A0000398.dll (Trojan.DownLoader) -> Quarantined and deleted successfully.
        E:\System Volume Information\_restore{F32A7D6C-7F82-4E40-82A8-63C3A783E380}\RP4\A0000423.exe (Worm.Socks) -> Quarantined and deleted successfully.
        E:\System Volume Information\_restore{F32A7D6C-7F82-4E40-82A8-63C3A783E380}\RP6\A0000487.exe (Adware.WhenUSave) -> Quarantined and deleted successfully.
        E:\WINDOWS\system32\blackster.scr (Trojan.Agent) -> Quarantined and deleted successfully.
        E:\WINDOWS\system32\ctfmonb.bmp (Malware.Trace) -> Quarantined and deleted successfully.
        E:\WINDOWS\system32\kezb427.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
        E:\WINDOWS\system32\kezb449.exe (Trojan.Inject) -> Quarantined and deleted successfully.
        E:\WINDOWS\system32\kezb472.exe (BackDoor.Bech) -> Quarantined and deleted successfully.
        E:\WINDOWS\system32\kezb534.exe (Trojan.DownLoader) -> Quarantined and deleted successfully.
        E:\WINDOWS\system32\kezb563.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
        E:\WINDOWS\system32\kezb573.exe (Trojan.BHO) -> Quarantined and deleted successfully.
        E:\WINDOWS\system32\kezb574.exe (Worm.Socks) -> Quarantined and deleted successfully.
        E:\WINDOWS\system32\kezb576.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        E:\WINDOWS\system32\wind32.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        E:\WINDOWS\system32\drivers\Cjp74.sys (Trojan.Downloader) -> Quarantined and deleted successfully.
        E:\WINDOWS\Temp\5CE8.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
        E:\WINDOWS\Temp\7755.tmp (Trojan.DownLoader) -> Quarantined and deleted successfully.
        E:\WINDOWS\Temp\836187518.exe (Trojan.Agent) -> Quarantined and deleted successfully.
        E:\WINDOWS\Temp\A08A.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
        E:\WINDOWS\Temp\loader.exe (Trojan.DownLoader) -> Quarantined and deleted successfully.
        E:\WINDOWS\Temp\win32.exe (Worm.Zhelatin) -> Quarantined and deleted successfully.
        E:\Program Files\MyWebSearch\bar\History\search2 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        E:\Program Files\MyWebSearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        E:\Program Files\Starware337\brand.bmp (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Program Files\Starware337\Starware337Config.xml (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Program Files\Starware337\Starware337Uninstall.exe (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Program Files\Starware337\bin\Starware337.dll (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Program Files\Starware337\icons\star_16.ico (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\All Users\Application Data\Starware337\buttons\epiRSS.bmp (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\All Users\Application Data\Starware337\buttons\epiRSS.png (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\All Users\Application Data\Starware337\buttons\epiSearch.bmp (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\All Users\Application Data\Starware337\buttons\epiSearch.png (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\All Users\Application Data\Starware337\buttons\FindIt.bmp (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\All Users\Application Data\Starware337\buttons\FindItHot.bmp (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\All Users\Application Data\Starware337\buttons\findithotxp.png (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\All Users\Application Data\Starware337\buttons\finditxp.png (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\All Users\Application Data\Starware337\buttons\Highlight.bmp (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\All Users\Application Data\Starware337\buttons\HighlightHot.bmp (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\All Users\Application Data\Starware337\buttons\highlighthotxp.png (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\All Users\Application Data\Starware337\buttons\highlightxp.png (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\All Users\Application Data\Starware337\buttons\logo.bmp (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\All Users\Application Data\Starware337\buttons\logoxp.bmp (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\All Users\Application Data\Starware337\buttons\Reference.bmp (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\All Users\Application Data\Starware337\buttons\ReferenceHot.bmp (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\All Users\Application Data\Starware337\buttons\referencehotxp.png (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\All Users\Application Data\Starware337\buttons\referencexp.png (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\All Users\Application Data\Starware337\buttons\Weather.bmp (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\All Users\Application Data\Starware337\buttons\weatherhotxp.png (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\All Users\Application Data\Starware337\buttons\weatherxp.png (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\All Users\Application Data\Starware337\contexts\error.xml (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\All Users\Application Data\Starware337\contexts\related.xml (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\All Users\Application Data\Starware337\contexts\travel.xml (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\All Users\Application Data\Starware337\images\walert.bmp (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\All Users\Application Data\Starware337\SimpleUpdate\ProductMessagingConfig.xml (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\All Users\Application Data\Starware337\SimpleUpdate\ProductMessagingConfig.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\All Users\Application Data\Starware337\SimpleUpdate\SimpleUpdateConfig.xml (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\All Users\Application Data\Starware337\SimpleUpdate\SimpleUpdateConfig.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\All Users\Application Data\Starware337\SimpleUpdate\TimerManagerConfig.xml (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\All Users\Application Data\Starware337\SimpleUpdate\TimerManagerConfig.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\BrowserSearch\BrowserSearch.xml (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\BrowserSearch\BrowserSearch.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\ErrorSearch\ErrorSearchOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\ErrorSearch\ErrorSearchOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\Games\GamesOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\Games\GamesOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\Games\images\active\Games0.bmp (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\Layouts\ToolbarLayout.xml (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\Layouts\ToolbarLayout.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\Manager\ManagerOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\Manager\ManagerOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\Movies\MoviesOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\Movies\MoviesOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\Movies\images\active\Movies0.bmp (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\Recipes\RecipesOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\Recipes\RecipesOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\RecipeSearch\RecipeSearchOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\RecipeSearch\RecipeSearchOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\Reference\ReferenceOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\Reference\ReferenceOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\RelatedSearch\RelatedSearchOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\RelatedSearch\RelatedSearchOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\ScreensaversMarketingSitePager\images\active\ScreensaversMarketingSitePager0.bmp (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\SearchAssistPlus\SearchAssistPlusOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\SearchAssistPlus\SearchAssistPlusOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\SearchMatch\SearchMatchOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\SearchMatch\SearchMatchOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\Toolbar\TBProductsOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\Toolbar\TBProductsOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\ToolbarLogo\ToolbarLogoOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\ToolbarLogo\ToolbarLogoOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\ToolbarSearch\ToolbarSearchOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\ToolbarSearch\ToolbarSearchOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\TravelSearch\TravelSearchOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\TravelSearch\TravelSearchOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\Weather\AlertArchive.xml (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\Weather\WeatherOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
        E:\Documents and Settings\jupiter\Application Data\Starware337\Weather\WeatherOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
        E:\WINDOWS\nivavir.config (Trojan.Agent) -> Quarantined and deleted successfully.
        E:\WINDOWS\kavir.exe (Trojan.Agent) -> Quarantined and deleted successfully.

        part 4 is next
        _______________________________________ ________________________


        lufo4

          Topic Starter


          Rookie

          Re: Bug screensaver virus
          « Reply #33 on: May 11, 2008, 12:02:54 PM »
          part 4

          _______________________________________ ________-

          E:\WINDOWS\system32\drivers\qandr.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
          E:\WINDOWS\system32\h@tkeysh@@k.dll (Trojan.Agent) -> Quarantined and deleted successfully.
          E:\WINDOWS\system32\__c0012A5B.dat (Trojan.Agent) -> Quarantined and deleted successfully.
          E:\WINDOWS\system32\__c0022FF9.dat (Trojan.Agent) -> Delete on reboot.
          E:\WINDOWS\system32\__c002C55C.dat (Trojan.Agent) -> Quarantined and deleted successfully.
          E:\WINDOWS\system32\__c003F351.dat (Trojan.Agent) -> Quarantined and deleted successfully.
          E:\WINDOWS\system32\__c0047B06.dat (Trojan.Agent) -> Quarantined and deleted successfully.
          E:\WINDOWS\system32\__c005EE10.dat (Trojan.Agent) -> Quarantined and deleted successfully.
          E:\WINDOWS\system32\__c0067F24.dat (Trojan.Agent) -> Quarantined and deleted successfully.
          E:\WINDOWS\system32\__c006999E.dat (Trojan.Agent) -> Quarantined and deleted successfully.
          E:\WINDOWS\system32\__c007798A.dat (Trojan.Agent) -> Quarantined and deleted successfully.
          E:\WINDOWS\system32\__c00A8F90.dat (Trojan.Agent) -> Quarantined and deleted successfully.
          E:\WINDOWS\system32\__c00B491.dat (Trojan.Agent) -> Quarantined and deleted successfully.
          E:\WINDOWS\system32\__c00BD6A1.dat (Trojan.Agent) -> Quarantined and deleted successfully.
          E:\WINDOWS\system32\__c00C710C.dat (Trojan.Agent) -> Quarantined and deleted successfully.
          E:\WINDOWS\system32\__c00DC690.dat (Trojan.Agent) -> Quarantined and deleted successfully.
          E:\WINDOWS\system32\basekdgtv32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
          E:\WINDOWS\Help\oqtxde.chm (Rootkit.Rustok) -> Quarantined and deleted successfully.
          E:\WINDOWS\system32\WLCtrl32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
          E:\WINDOWS\system32\ctfmona.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
          E:\WINDOWS\system32\basenpnv32.dll (Trojan.Downloader) -> Delete on reboot.
          E:\WINDOWS\system32\lost.exe.exe (Worm.Zhelatin) -> Quarantined and deleted successfully.
          E:\WINDOWS\system32\dllgh8jkd1q1.exe (Heuristics.Malware) -> Quarantined and deleted successfully.
          E:\WINDOWS\system32\dllgh8jkd1q2.exe (Heuristics.Malware) -> Quarantined and deleted successfully.
          E:\WINDOWS\system32\dllgh8jkd1q5.exe (Heuristics.Malware) -> Quarantined and deleted successfully.
          E:\WINDOWS\system32\dllgh8jkd1q6.exe (Heuristics.Malware) -> Quarantined and deleted successfully.
          E:\WINDOWS\system32\dllgh8jkd1q7.exe (Heuristics.Malware) -> Quarantined and deleted successfully.
          E:\WINDOWS\system32\dllgh8jkd1q8.exe (Heuristics.Malware) -> Quarantined and deleted successfully.
          E:\WINDOWS\system32\winsub.xml (Malware.Trace) -> Quarantined and deleted successfully.
          E:\WINDOWS\system32\maxpaynowti1.exe (Heuristics.Malware) -> Quarantined and deleted successfully.
          E:\WINDOWS\system32\__c004B1A3.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
          E:\WINDOWS\system32\vx.tll (Malware.Trace) -> Quarantined and deleted successfully.
          E:\WINDOWS\Temp\1.dllb (Heuristics.Malware) -> Quarantined and deleted successfully.
          E:\WINDOWS\Temp\2.dllb (Heuristics.Malware) -> Quarantined and deleted successfully.
          E:\WINDOWS\Temp\5.dllb (Heuristics.Malware) -> Quarantined and deleted successfully.
          E:\WINDOWS\Temp\6.dllb (Heuristics.Malware) -> Quarantined and deleted successfully.
          E:\WINDOWS\Temp\7.dllb (Heuristics.Malware) -> Quarantined and deleted successfully.
          E:\WINDOWS\system32\svchost.t__ (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.

          Broni


            Mastermind
          • Kraków my love :)
          • Thanked: 614
            • Computer Help Forum
          • Computer: Specs
          • Experience: Experienced
          • OS: Windows 8
          Re: Bug screensaver virus
          « Reply #34 on: May 11, 2008, 12:04:24 PM »
          That's it? It was quiet a bit :)
          Fresh HJT log, please.

          kidjete



            Starter

            Re: Bug screensaver virus
            « Reply #35 on: May 21, 2008, 01:39:49 AM »
            I had a similar problem and followed your steps.  Would you mind taking a look at my logs?  I couldn't find the SAS log after I rebooted from safe mode after running it, I forgot to save it I think.  SAS and Malwarebytes both found and deleted files.  I'm not real familiar with HJT so I just ran the log and didn't touch anything else yet.   Anyway here's the Malwarebytes' and HJT logs...



            Malwarebytes' Anti-Malware 1.12
            Database version: 772

            Scan type: Full Scan (C:\|)
            Objects scanned: 198636
            Time elapsed: 1 hour(s), 9 minute(s), 12 second(s)

            Memory Processes Infected: 0
            Memory Modules Infected: 1
            Registry Keys Infected: 2
            Registry Values Infected: 1
            Registry Data Items Infected: 0
            Folders Infected: 0
            Files Infected: 3

            Memory Processes Infected:
            (No malicious items detected)

            Memory Modules Infected:
            C:\WINDOWS\system32\baseksqn32.dll (Trojan.Downloader) -> Unloaded module successfully.

            Registry Keys Infected:
            HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SysLibrary (Rootkit.Agent) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.

            Registry Values Infected:
            HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\herjek (Trojan.Agent) -> Quarantined and deleted successfully.

            Registry Data Items Infected:
            (No malicious items detected)

            Folders Infected:
            (No malicious items detected)

            Files Infected:
            C:\Program Files\Absolute Poker\browser.exe (Trojan.Agent) -> Quarantined and deleted successfully.
            C:\WINDOWS\herjek.exe (Trojan.Agent) -> Quarantined and deleted successfully.
            C:\WINDOWS\system32\baseksqn32.dll (Trojan.Downloader) -> Delete on reboot.






            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 3:32:33 AM, on 5/21/2008
            Platform: Windows XP SP3 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16640)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Bonjour\mDNSResponder.exe
            C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            C:\WINDOWS\runservice.exe
            C:\Program Files\McAfee\Common Framework\FrameworkService.exe
            C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
            C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\TVersity\Media Server\MediaServer.exe
            C:\Program Files\Viewpoint\Common\ViewpointService.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\SOUNDMAN.EXE
            C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
            C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
            C:\Program Files\Logitech\MouseWare\system\em_exec.exe
            C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
            C:\Program Files\McAfee\Common Framework\UdaterUI.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
            C:\Program Files\McAfee\Common Framework\McTray.exe
            C:\Program Files\VIA\RAID\raid_tool.exe
            C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
            C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://flashmail.kent.edu/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxy.kent.edu/
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
            O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
            O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
            O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
            O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
            O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
            O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
            O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
            O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
            O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
            O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
            O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
            O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
            O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
            O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
            O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
            O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
            O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
            O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
            O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
            O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
            O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Chad Muniz\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
            O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Chad Muniz\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
            O9 - Extra button: PartyGammon.com - {59A861EE-32B3-42cd-8CCA-FC130EDF3A44} - C:\WINDOWS\System32\shdocvw.dll
            O9 - Extra 'Tools' menuitem: PartyGammon.com - {59A861EE-32B3-42cd-8CCA-FC130EDF3A44} - C:\WINDOWS\System32\shdocvw.dll
            O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
            O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
            O9 - Extra button: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\WINDOWS\System32\shdocvw.dll
            O9 - Extra 'Tools' menuitem: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\WINDOWS\System32\shdocvw.dll
            O9 - Extra button: PartyBingo.com - {B987E7E7-5997-4330-A5F9-9FFEFC1CCFD0} - C:\WINDOWS\System32\shdocvw.dll
            O9 - Extra 'Tools' menuitem: PartyBingo.com - {B987E7E7-5997-4330-A5F9-9FFEFC1CCFD0} - C:\WINDOWS\System32\shdocvw.dll
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
            O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
            O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
            O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
            O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
            O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install/installer.exe
            O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Branding/olr3313/OCX/v1018/flashax.cab
            O16 - DPF: {DA80E089-4648-43D5-93B4-7F37917084E6} (CacheManager.CacheManagerCtrl) - http://www.candystand.com/assets/activex/virtools/CacheManager.CAB
            O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
            O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
            O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
            O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
            O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
            O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
            O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
            O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
            O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
            O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
            O23 - Service: TVersityMediaServer - Unknown owner - C:\Program Files\TVersity\Media Server\MediaServer.exe
            O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

            --
            End of file - 11591 bytes

            evilfantasy

            • Malware Removal Specialist
            • Moderator


            • Genius
            • Calm like a bomb
            • Thanked: 493
            • Experience: Experienced
            • OS: Windows 11
            Re: Bug screensaver virus
            « Reply #36 on: May 21, 2008, 09:54:42 AM »
            kidjete start a new topic in this forum and post the logs there. We can't work on your logs in the same thread. You need your own topic.

            kidjete



              Starter

              Re: Bug screensaver virus
              « Reply #37 on: May 21, 2008, 02:14:32 PM »
              kidjete start a new topic in this forum and post the logs there. We can't work on your logs in the same thread. You need your own topic.

              Why not?  That doesn't make a lot of sense.  We had the same issue why not use the same thread so there is more than one example?  Whatever though I'll post a new thread.

              mcxeb52!

              • Guest
              Re: Bug screensaver virus
              « Reply #38 on: May 21, 2008, 10:19:27 PM »
              kidjete start a new topic in this forum and post the logs there. We can't work on your logs in the same thread. You need your own topic.

              Why not?  That doesn't make a lot of sense.  We had the same issue why not use the same thread so there is more than one example?  Whatever though I'll post a new thread.

              one needs his own thread. his own computer logs may confuse the original poster. make your own post and the other guy shall be directed to the new post if needed.

              sallymae

              • Guest
              Re: Bug screensaver virus
              « Reply #39 on: May 23, 2008, 02:40:34 PM »
              I had this same thing happen on a system where I work.  I found out it was a screensaver named blackster.scr from a screensaver program on the Internet named Bugs 2.0.2.  I found the entry in the registry where it was running the screensaver blackster.scr and replaced it with ssstars.scr from Windows.  Then I deleted the blackster.scr file from the system.  The original virus was ctfmona.exe which I also had to manually remove from the system.  We run Trend Micro Office Scan Virus Protection and it caught it but could not quarantine it.  After I removed the virus and got clean scans, I still had the screensaver issue.  Now that I have removed it, I am hoping the system is really clean now.  Time will tell.

              evilfantasy

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Calm like a bomb
              • Thanked: 493
              • Experience: Experienced
              • OS: Windows 11
              Re: Bug screensaver virus
              « Reply #40 on: May 23, 2008, 03:38:13 PM »
              Welcome to CH sallymae.

              The best way to find out if you are clean is to start a new topic. Click  here >> << and post a Hijackthis log for a malware specialist to look at.

              Download and rename HijackThis (HJT)
              • Double-click on HJTInstall.
              • Click on the Install button.
              • It will automatically place HJT in C:\Program Files\TrendMicro\HijackThis\HijackThis.exe.
              • Upon install, HijackThis should open for you.
              • Close HijackThis and rename it.
              • Go to C:\Program Files\Trend Micro\HijackThis.exe
              • Right click on HijackThis.exe and select Rename.
              • Type in sniper.exe and press Enter.
              • Right-click on sniper.exe and select Send To > Desktop (create shortcut)
              • From the desktop open Hijackthis.
              • If using Windows Vista, Right-click and Run As Administrator.
              • Click on the Do a system scan and save a log file button
              • Hijackthis will scan and then a log will open in notepad.
              • Copy and then paste the entire contents of the log in your post.
              • Do not have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.
              Although we have renamed Hijackthis to sniper, we will still refer to it as Hijackthis or HJT.

              CBMatt

              • Mod & Malware Specialist


              • Prodigy

              • Sad and lonely...and loving every minute of it.
              • Thanked: 167
                • Yes
              • Experience: Experienced
              • OS: Windows 7
              Quote
              An undefined problem has an infinite number of solutions.
              —Robert A. Humphrey