Showing posts with label Rogue antimalware. Show all posts
Showing posts with label Rogue antimalware. Show all posts
Azlan Mahmud
LOL, its funny that my virtual pc that is infected with Antivirus 2009 and other crap. Antivirus 2009 create a log... So funny..

Antivirus 2009 system scan report.
Report generated 24.12.2008 15:49:03

Type Run type Name Details
Spyware C://windows/system32/iesetup.dll Spyware.IEMonster.d "Steals passwords from Internet Explorer, Mozilla Firefox, Outlook and other programs.
Adware autorun Zlob.PornAdvertiser.ba Adware that displays pop-up/pop-under advertisements of pornographic or online gambling Web sites.
Spyware autorun Spyware.IMMonitor program that can be used to monitor and record conversations in popular instant messaging applications.
Backdoor C://windows/system32/svchost.exe Win32.Rbot.fm An IRC controlled backdoor that can be used to gain unauthorized access to a victim's machine.
Trojan autorun Infostealer.Banker.E Steals sensitive information from the infected computer (e.g. logins and passwords from online banking sessions).
Dialer C://windows/system32/cmdial32.dll Dialer.Xpehbam.biz_dialer A Dialer that loads pornographic material. The url information shows Hardcore Pornographic pages.
Spyware autorun Spyware.KnownBadSites Uses the Windows hosts file to redirect your browser to a malicious site when you try to access a valid site.
Trojan autorun Trojan.Tooso Trojan.Tooso is a trojan which attempts to terminate and delete security related applications.
Trojan C://windows/system32/explorer.exe Trojan.MailGrabber.s Trojan horse that gets access to e-mail accounts on the infected computer.
Trojan C://windows/system32/alg.exe Trojan.Alg.t Trojan program that can compromise your private information stored on the hard drive.
Rogue C://Program Files/TrustedAntivirus TrustedAntivirus A corrupt and misleading anti-virus program that may be usually installed with the help of malcous Trojans and other malware
Rogue C://Program Files/SecurePCCleaner SecurePCCleaner Rogue Security Software: fake Security software that uses deceptive means for installation and purpose.
Trojan C://windows/system32/ Trojan.BAT.Adduser.t This Trojan has a malicious payload. It is a BAT file. It is 1129 bytes in size.
Spyware C://windows/system32/ Spyware.007SpySoftware Program designed to monitor user activity. May be used with or without consent.
Trojan C://windows/hidden/ Trojan.Clicker.EC Trojan.Clicker.EC is an information stealing Trojan that masquerades as a legitimate system file so as to avoid detection and subsequent removal.
Dialer C://windows/hidden/ Dialer.Trafficjam.a Dialer.Trafficjam.a is a premium-rate phone dialer that automatically invokes paid access to various porn-related Web sites.
Trojan hidden autorun Trojan.Poison.J Trojan.Poison.J is a key-logging Trojan for the Windows platform.
Adware Registry Adware.eXact.BargainBuddy A browser helper object that monitors internet browsing sessions in an attempt to redirect search queries and distribute unsolicited advertisements.
Worm C://windows/system32/ Win32.Delbot.AI Win32.Delbot.AI is a worm and IRC backdoor that exploits system and software vulnerabilities in order to provide remote access to the host PC.
Worm C://windows/temp/ Win32.Sdbot.ADN A worm and IRC backdoor that exploits system and software vulnerabilities in order to provide unmitigated remote access to the host machine.
Trojan C://windows/ Trojan-Dropper.Win32.Agent.bot This Trojan is designed to install and launch other malicious programs on the victim machine without the knowledge or consent of the user.
Worm C://windows/temp/ Win32.Rbot.CBX A worm and IRC backdoor that exploits system and software vulnerabilities in order to provide unmitigated remote access to the host machine.
Spyware autorun Win32.PerFiler Win32.PerFiler is designed to retrieve and install files when executed. Win32.PerFiler is configured to download from either a designated web or FTP site.
Worm hidden autorun Win32.Miewer.a A Trojan Downloader that masquerades as a legitimate system file. Associated processes connect to the Internet to download additional malicious files
Trojan C://windows/ Trojan-Downloader.VBS.Small.dc This Trojan downloads other files via the FTP protocol and launches them for execution on the victim machine without the user’s knowledge.
Worm autorun Win32.Peacomm.dam A Trojan Downloader that is spread as an attachment to emails with news headlines as the subject lines which downloads additional security threats.
Trojan C://windows/system/drivers/ Win32.Spamta.KG.worm A multi-component mass-mailing worm that downloads and executes files from the Internet.
Trojan C://windows/system/drivers/etc/ Trojan.IRCBot.d a worm that opens an IRC back door on the infected host. It spreads by exploiting the Windows Remote Buffer Overflow Vulnerability.
Trojan C://windows/system/mui/ Trojan.Dropper.MSWord.j A Microsoft Word macro virus that drops a trojan onto the infected host.
Trojan C://windows/system/mui/ Win32.Clagger.C This is small Trojan downloader that downloads files and lowers security settings. It is spreading as an email attachment.
Worm C://windows/system/ Worm.Bagle.CP This is a ""Bagle"" mass-mailer which demonstrates typical ""Bagle"" behavior.
Worm C://windows/ Win32.BlackMail.xx "This dangerous worm will destroy certain data files on an infected user's machine on February 3, 2008.
Trojan hidden autorun Trojan.Win32.Agent.ado Trojan downloader that is spread as an attachment to a spam email and tries to download a password stealer.
Trojan autorun Win32.Outsbot.u A backdoor Trojan that is remotely controlled via Internet Relay Chat (IRC). It exploits Sony Digital Rights Management (DRM) software to hide its presence.
Worm hidden autorun Win32.Sober.P This is a mass-mailing worm that uses its own SMTP engine to spread. It sends itself as an email attachment that mimics an image file.
Worm C://windows/temp/ Win32.Sdbot.ADN A worm and IRC backdoor that exploits system and software vulnerabilities in order to provide unmitigated remote access to the host machine.
Trojan C://windows/ Trojan-Dropper.Win32.Agent.bot This Trojan is designed to install and launch other malicious programs on the victim machine without the knowledge or consent of the user.
Worm C://windows/temp/ Win32.Rbot.CBX A worm and IRC backdoor that exploits system and software vulnerabilities in order to provide unmitigated remote access to the host machine.
Spyware autorun Win32.PerFiler Win32.PerFiler is designed to retrieve and install files when executed. Win32.PerFiler is configured to download from either a designated web or FTP site.
Worm hidden autorun Win32.Miewer.a A Trojan Downloader that masquerades as a legitimate system file.
Tracking Cookie Web browser ad.yieldmanager C:\Documents and Settings\Azlan\Cookies\azlan@ad.yieldmanager[2].txt
Tracking Cookie Web browser auto.search.msn C:\Documents and Settings\Azlan\Cookies\azlan@auto.search.msn[2].txt
Tracking Cookie Web browser avgtechnologies.112.2o7 C:\Documents and Settings\Azlan\Cookies\azlan@avgtechnologies.112.2o7[1].txt
Tracking Cookie Web browser msantispyware C:\Documents and Settings\Azlan\Cookies\azlan@msantispyware[1].txt
Tracking Cookie Web browser mywebsearch.smileycentral C:\Documents and Settings\Azlan\Cookies\azlan@mywebsearch.smileycentral[1].txt
Tracking Cookie Web browser mywebsearch C:\Documents and Settings\Azlan\Cookies\azlan@mywebsearch[2].txt
Tracking Cookie Web browser rad.microsoft C:\Documents and Settings\Azlan\Cookies\azlan@rad.microsoft[2].txt
Tracking Cookie Web browser rad.msn C:\Documents and Settings\Azlan\Cookies\azlan@rad.msn[2].txt
Tracking Cookie Web browser search.live C:\Documents and Settings\Azlan\Cookies\azlan@search.live[1].txt
Tracking Cookie Web browser search.msn C:\Documents and Settings\Azlan\Cookies\azlan@search.msn[1].txt
Tracking Cookie Web browser searchportal.information C:\Documents and Settings\Azlan\Cookies\azlan@searchportal.information[1].txt
Tracking Cookie Web browser sp2.information C:\Documents and Settings\Azlan\Cookies\azlan@sp2.information[1].txt
Tracking Cookie Web browser statcounter C:\Documents and Settings\Azlan\Cookies\azlan@statcounter[2].txt
Tracking Cookie Web browser login.live C:\Documents and Settings\Azlan\Cookies\system@login.live[1].txt
Tracking Cookie Web browser msnaccountservices.112.2o7 C:\Documents and Settings\Azlan\Cookies\system@msnaccountservices.112.2o7[2].txt
Tracking Cookie Web browser rad.msn C:\Documents and Settings\Azlan\Cookies\system@rad.msn[2].txt
Azlan Mahmud
I just downloaded Malwarebytes and SUPERAntispyware

This is hte malwarebytes log file after complete scan (didnt complete the scan)

Malwarebytes' Anti-Malware 1.30
Database version: 1412
Windows 6.0.6001 Service Pack 1

20/11/2008 9:26:54 PM
mbam-log-2008-11-20 (21-26-54).txt

Scan type: Full Scan (C:\|)
Objects scanned: 71132
Time elapsed: 41 minute(s), 55 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 8

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Users\Mahmud65\AppData\Local\Temp\ssqRHXNf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Mahmud65\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I3VI8O85\iolhvi[1].htm (Trojan.TinyDownloader705) -> Quarantined and deleted successfully.
C:\Users\Mahmud65\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CAUO8A5Y\xgqere[1].htm (Trojan.TinyDownloader705) -> Quarantined and deleted successfully.
C:\Users\Mahmud65\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8KAUE6CH\bhrrfs[1].htm (Trojan.TinyDownloader705) -> Quarantined and deleted successfully.
C:\Users\Mahmud65\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8KAUE6CH\apstpldr.dll[1].htm (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Mahmud65\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\57JEKC44\rkkhlmmzax[1].htm (Trojan.TinyDownloader705) -> Quarantined and deleted successfully.
C:\Users\Mahmud65\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\57JEKC44\rblllmqd[1].htm (Trojan.TinyDownloader705) -> Quarantined and deleted successfully.
C:\Users\Mahmud65\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\57JEKC44\bherswjkk[1].txt (Trojan.Dropper) -> Quarantined and deleted successfully.

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 11/19/2008 at 10:06 PM

Application Version : 4.21.1004

Core Rules Database Version : 3643
Trace Rules Database Version: 1626

Scan type : Complete Scan
Total Scan Time : 00:10:18

Memory items scanned : 616
Memory threats detected : 0
Registry items scanned : 6679
Registry threats detected : 1
File items scanned : 0
File threats detected : 1

Adware.Vundo/Variant-Greek
[MSServer] C:\USERS\MAHMUD65\APPDATA\LOCAL\TEMP\XXYYXYVM.DLL
C:\USERS\MAHMUD65\APPDATA\LOCAL\TEMP\XXYYXYVM.DLL

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 11/20/2008 at 12:25 PM

Application Version : 4.21.1004

Core Rules Database Version : 3644
Trace Rules Database Version: 1627

Scan type : Quick Scan
Total Scan Time : 00:09:53

Memory items scanned : 583
Memory threats detected : 0
Registry items scanned : 427
Registry threats detected : 0
File items scanned : 1917
File threats detected : 1

Adware.Vundo/Variant-Greek
C:\$RECYCLE.BIN\S-1-5-21-3758004346-2321403008-2544184651-1003\$RGDA2QX.EXE
Azlan Mahmud
Antivirus 2010 is fake antispyware program from the same family as eAntivirusPro, AntiMalware 2009, Micro Antivirus 2009, Vista Antivirus 2008, Antispyware 2008 XP, System Antivirus 2008, Internet Antivirus, Smart Antivirus 2009, MS Antivirus, Advanced Antivirus, Power Antivirus, XPert Antivirus. Like other rogue antispyware programs, it uses malicious programs and advertising on the Internet for distribution. This advertisement tells that your computer is infected and offers to download and install Antivirus 2010. Also the program may use trojans for invisible installation on your computer. During installation, it configures itself to run automatically every time, when you start your computer.

Immediately after launch, the program starts scanning the computer and found a lot of trojans and spyware.



Then, it said that you should purchase Antivirus 2010 in order to remove them and protect your PC. Do not do it!

Symptoms in a HijackThis Log:

O2 - BHO: IEDefenderBHO - {FC8A493F-D236-4653-9A03-2BF4FD94F643} - C:\Windows\System32\IEDefender.dll
O4 - HKLM\..\Run: [Windows Gamma Display] C:\Windows\System32\wingamma.exe /adjustment

How to remove Antivirus 2010:
1. Using SmitfraudFix.

* Download SmitfraudFix.( google search it)
# Reboot your computer in Safe Mode by doing the following:

1. Restart your computer
2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3. Instead of Windows loading as normal, a menu should appear
4. Select the first option, to run Windows in Safe Mode.

# Double-click SmitfraudFix.exe.
# Press the number 2 on your keyboard and the press the enter key to choose the option Clean (safe mode recommended).
# You will be prompted : “Registry cleaning - Do you want to clean the registry ?“; answer “Yes” by typing Y and press “Enter” in order to remove the Desktop background and clean registry keys associated with the infection.
# The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer “Yes” by typing Y and press “Enter”.
# The tool may need to restart your computer to finish the cleaning process; if it doesn’t, please restart it into Normal Windows.



2. Using Malwarebytes Anti-Malware.

* Download MalwareBytes Anti-malware (MBAM). Close all programs and Windows on your computer.
* Double Click mbam-setup.exe to install the application. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure a checkmark is placed next to Update Malwarebytes’ Anti-Malware and Launch Malwarebytes’ Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select “Perform Quick Scan”, then click Scan.
* The scan may take some time to finish,so please be patient.
* When the scan is complete, click OK, then Show Results to view the results.
* Make sure that everything is checked, and click Remove Selected.
* When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.

Antivirus 2010 creates the following files and folders:

c:\Documents and Settings\All Users\Start Menu\Programs\av2010
c:\Documents and Settings\All Users\Desktop\av2010.lnk
c:\Program Files\av2010
c:\Program Files\AV2010\AV2010.exe
c:\Program Files\AV2010\svchost.exe
c:\WINDOWS\system32\IEDefender.dll
c:\WINDOWS\system32\wingamma.exe