Halo00man
Topic Starter
Hello, I reformat my computer probably once every 2-3 months to clear potential spyware/virus and because for some reason I find it enjoyable. But that's besides the point. Last night I had some virus from some stupid "throw up" video websites(like 2 girls 1 cup, but not that one) and since I hadn't reformated in a while, I decided to do it this afternoon. I reformatted, everything was going well, until I got a random ad. The same ads I was getting from the virus that I got from that website. I was really shocked. The only things I downloaded onto my computer were essential, safe things like winrar, vlc, adobe flash etc. The only thing I took from my flash drive were drivers and a folder with files in it(nothing malicious). I downloaded malwarebyte's anti-malaware, ran a quick scan and came up with a whopping 20 virus's. I restarted my computer, did the same thing and the same 20 virus's were still there even though I thought they were deleted. Please help! I will post my hijackthis log and malwarebytes log.
Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org
Database version: 3973
Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512
4/10/2010 3:18:33 AM
mbam-log-2010-04-10 (03-18-33).txt
Scan type: Quick scan
Objects scanned: 105036
Time elapsed: 3 minute(s), 44 second(s)
Memory Processes Infected: 2
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 2
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 10
Memory Processes Infected:
C:\WINDOWS\Yjabua.exe (Trojan.FraudPack) -> Unloaded process successfully.
C:\Documents and Settings\Blake Foster\Local Settings\Temp\Ypg.exe (Trojan.FraudPack) -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{28abc5c0-4fcb-11cf-aax5-81cx1c635612} (Generic.Bot.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\YVIBBBHA8C (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\WEK9EMDHI9 (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\yvibbbha8c (Trojan.FraudPack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchost32 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 93.188.163.54,93.188.166.137 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{651c1fd7-15af-428e-8ac3-609ab66f32e2}\NameServer (Trojan.DNSChanger) -> Data: 93.188.163.54,93.188.166.137 -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\SYSTEMFILES\x-f-324553-12314-3344-1\ise32.exe (Generic.Bot.H) -> Delete on reboot.
C:\WINDOWS\Yjabua.exe (Trojan.FraudPack) -> Quarantined and deleted successfully.
C:\Documents and Settings\Blake Foster\Local Settings\Temp\Ypg.exe (Trojan.FraudPack) -> Quarantined and deleted successfully.
C:\Documents and Settings\Blake Foster\Local Settings\Temp\000002fd (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Blake Foster\Local Settings\Temp\Ypf.exe (Trojan.FraudPack) -> Quarantined and deleted successfully.
C:\Documents and Settings\Blake Foster\Local Settings\Temporary Internet Files\Content.IE5\T7GHCNLW\install[1].48636.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\spool\prtprocs\w32x86\00001b15.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Blake Foster\Application Data\svchost32.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:18:59 AM, on 4/10/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Blake Foster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Blake Foster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Blake Foster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Blake Foster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Documents and Settings\Blake Foster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Blake Foster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Blake Foster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Blake Foster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Blake Foster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Blake Foster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Documents and Settings\Blake Foster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Blake Foster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\RunOnce: [Uninstall Adobe Download Manager] "C:\WINDOWS\system32\rundll32.exe" "C:\Program Files\NOS\bin\getPlus_Helper.dll",Uninstall /IE2883E8F-472F-4fb0-9522-AC9BF37916A7 /Get1noarp
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Blake Foster\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
–
End of file - 4112 bytes
Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org
Database version: 3973
Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512
4/10/2010 3:18:33 AM
mbam-log-2010-04-10 (03-18-33).txt
Scan type: Quick scan
Objects scanned: 105036
Time elapsed: 3 minute(s), 44 second(s)
Memory Processes Infected: 2
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 2
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 10
Memory Processes Infected:
C:\WINDOWS\Yjabua.exe (Trojan.FraudPack) -> Unloaded process successfully.
C:\Documents and Settings\Blake Foster\Local Settings\Temp\Ypg.exe (Trojan.FraudPack) -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{28abc5c0-4fcb-11cf-aax5-81cx1c635612} (Generic.Bot.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\YVIBBBHA8C (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\WEK9EMDHI9 (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\yvibbbha8c (Trojan.FraudPack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchost32 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 93.188.163.54,93.188.166.137 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{651c1fd7-15af-428e-8ac3-609ab66f32e2}\NameServer (Trojan.DNSChanger) -> Data: 93.188.163.54,93.188.166.137 -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\SYSTEMFILES\x-f-324553-12314-3344-1\ise32.exe (Generic.Bot.H) -> Delete on reboot.
C:\WINDOWS\Yjabua.exe (Trojan.FraudPack) -> Quarantined and deleted successfully.
C:\Documents and Settings\Blake Foster\Local Settings\Temp\Ypg.exe (Trojan.FraudPack) -> Quarantined and deleted successfully.
C:\Documents and Settings\Blake Foster\Local Settings\Temp\000002fd (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Blake Foster\Local Settings\Temp\Ypf.exe (Trojan.FraudPack) -> Quarantined and deleted successfully.
C:\Documents and Settings\Blake Foster\Local Settings\Temporary Internet Files\Content.IE5\T7GHCNLW\install[1].48636.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\spool\prtprocs\w32x86\00001b15.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Blake Foster\Application Data\svchost32.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:18:59 AM, on 4/10/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Blake Foster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Blake Foster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Blake Foster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Blake Foster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Documents and Settings\Blake Foster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Blake Foster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Blake Foster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Blake Foster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Blake Foster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Blake Foster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Documents and Settings\Blake Foster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Blake Foster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\RunOnce: [Uninstall Adobe Download Manager] "C:\WINDOWS\system32\rundll32.exe" "C:\Program Files\NOS\bin\getPlus_Helper.dll",Uninstall /IE2883E8F-472F-4fb0-9522-AC9BF37916A7 /Get1noarp
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Blake Foster\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
–
End of file - 4112 bytes