This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] hidrag.a and probably a few others

94 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Atf cleaner successfully executed ant cleaned everything. Still no luck with the manual command. Same errors as before and no log. You didnt instruct me to dl hjt yet. I cant post a hjt log.
If you wish, edit the previous pasted instruction to not include "along with a HJT log". Quick scan or full scan?
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
rebooting

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4058

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

5/1/2010 9:19:35 PM
mbam-log-2010-05-01 (21-19-35).txt

Scan type: Quick scan
Objects scanned: 116930
Time elapsed: 6 minute(s), 56 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 3
Registry Keys Infected: 1
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 46

Memory Processes Infected:
C:\Windows\svchost.exe (Trojan.Agent) -> Unloaded process successfully.

Memory Modules Infected:
C:\Windows\Temp\qqaA2A4.tmp (Worm.Parite) -> Delete on reboot.
C:\Windows\Temp\nia5984.tmp (Worm.Parite) -> Delete on reboot.
C:\Windows\Temp\taa8C6.tmp (Worm.Parite) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\powermanager (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\syncman (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\syncman (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\Windows\System32\wuaucldt.exe (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
C:\Windows\Temp\qqaA2A4.tmp (Worm.Parite) -> Delete on reboot.
C:\Windows\Temp\nia5984.tmp (Worm.Parite) -> Delete on reboot.
C:\Windows\Temp\taa8C6.tmp (Worm.Parite) -> Delete on reboot.
C:\Windows\System32\123562.exe (Trojan.Refpron) -> Quarantined and deleted successfully.
C:\Windows\System32\1277211.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Windows\System32\1925405.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Windows\System32\4083826.exe (Trojan.Refpron) -> Quarantined and deleted successfully.
C:\Windows\System32\5765933.exe (Trojan.Refpron) -> Quarantined and deleted successfully.
C:\Windows\System32\6264241.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Windows\System32\7978174.exe (Trojan.Refpron) -> Quarantined and deleted successfully.
C:\Windows\System32\d.bin (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Windows\System32\ms.bin (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\System32\so.bin (Trojan.Koblu) -> Quarantined and deleted successfully.
C:\Windows\System32\839742.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Windows\System32\9521448.exe (Trojan.Refpron) -> Quarantined and deleted successfully.
C:\Windows\Temp\kpa9B64.tmp (Worm.Parite) -> Quarantined and deleted successfully.
C:\Windows\Temp\lsaB96F.tmp (Worm.Parite) -> Quarantined and deleted successfully.
C:\Windows\Temp\wfa34E4.tmp (Worm.Parite) -> Quarantined and deleted successfully.
C:\Windows\Temp\wsaB6DF.tmp (Worm.Parite) -> Quarantined and deleted successfully.
C:\Windows\Temp\wvaD6DD.tmp (Worm.Parite) -> Quarantined and deleted successfully.
C:\Windows\Temp\oxaEA8C.tmp (Worm.Parite) -> Quarantined and deleted successfully.
C:\Windows\Temp\pem2F9A.tmp (Worm.Parite) -> Quarantined and deleted successfully.
C:\Windows\Temp\poa8E98.tmp (Worm.Parite) -> Quarantined and deleted successfully.
C:\Windows\Temp\ptaBE9D.tmp (Worm.Parite) -> Quarantined and deleted successfully.
C:\Windows\Temp\rca1DAD.tmp (Worm.Parite) -> Quarantined and deleted successfully.
C:\Windows\Temp\nok9483.tmp (Worm.Parite) -> Quarantined and deleted successfully.
C:\Windows\Temp\nraAB8A.tmp (Worm.Parite) -> Quarantined and deleted successfully.
C:\Windows\Temp\tna88BE.tmp (Worm.Parite) -> Quarantined and deleted successfully.
C:\Windows\Temp\ucb1DCC.tmp (Worm.Parite) -> Quarantined and deleted successfully.
C:\Windows\Temp\uka64CA.tmp (Worm.Parite) -> Quarantined and deleted successfully.
C:\Windows\Temp\VRT426C.tmp (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Windows\Temp\VRT48B2.tmp (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Windows\Temp\VRT80A3.tmp (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Windows\Temp\VRT86CB.tmp (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Windows\Temp\zkm6BFD.tmp (Worm.Parite) -> Quarantined and deleted successfully.
C:\Windows\Temp\zxaEAFA.tmp (Worm.Parite) -> Quarantined and deleted successfully.
C:\Windows\Temp\euaCA31.tmp (Worm.Parite) -> Quarantined and deleted successfully.
C:\Windows\Temp\eybF22B.tmp (Worm.Parite) -> Quarantined and deleted successfully.
C:\Windows\Temp\jec2C5D.tmp (Worm.Parite) -> Quarantined and deleted successfully.
C:\Windows\Temp\jja625A.tmp (Worm.Parite) -> Quarantined and deleted successfully.
C:\Windows\Temp\staC4B5.tmp (Worm.Parite) -> Quarantined and deleted successfully.
C:\Windows\Temp\syhF0B5.tmp (Worm.Parite) -> Quarantined and deleted successfully.
C:\Windows\System32\config\systemprofile\wuaucldt.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\System32\w.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Windows\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
same infections… different files and a little less of them.
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4058

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

5/1/2010 9:36:27 PM
mbam-log-2010-05-01 (21-36-27).txt

Scan type: Quick scan
Objects scanned: 117021
Time elapsed: 7 minute(s), 52 second(s)

Memory Processes Infected: 3
Memory Modules Infected: 4
Registry Keys Infected: 2
Registry Values Infected: 12
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 20

Memory Processes Infected:
C:\Windows\System32\PereSvc.exe (Trojan.Koblu) -> Unloaded process successfully.
C:\Windows\System32\w.exe (Backdoor.Bot) -> Unloaded process successfully.
c:\Windows\System32\wuaucldt.exe (Trojan.Agent) -> Unloaded process successfully.

Memory Modules Infected:
C:\Windows\Temp\uyaF3D0.tmp (Worm.Parite) -> Delete on reboot.
C:\Windows\Temp\wwaE1E5.tmp (Worm.Parite) -> Delete on reboot.
C:\Users\Bryan\AppData\Local\Temp\wyaF2E5.tmp (Worm.Parite) -> Delete on reboot.
C:\Windows\System32\BtwSvc.dll (Trojan.Agent) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\btwsvc (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\peresvc (Trojan.Koblu) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\syncman (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\syncman (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\buildw (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\firstinstallflag (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\guid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\i (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\uid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ulrn (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\update (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\updatenew (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\mbt (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\mpe (Malware.Trace) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\Windows\System32\wuaucldt.exe (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
C:\Windows\Temp\uyaF3D0.tmp (Worm.Parite) -> Delete on reboot.
C:\Windows\Temp\wwaE1E5.tmp (Worm.Parite) -> Delete on reboot.
C:\Users\Bryan\AppData\Local\Temp\wyaF2E5.tmp (Worm.Parite) -> Delete on reboot.
C:\Windows\System32\BtwSvc.dll (Trojan.Agent) -> Delete on reboot.
C:\Windows\System32\PereSvc.exe (Trojan.Koblu) -> Quarantined and deleted successfully.
C:\Windows\System32\3263143.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Windows\System32\d.bin (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Windows\System32\ms.bin (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\System32\so.bin (Trojan.Koblu) -> Quarantined and deleted successfully.
C:\Windows\Temp\fvaD538.tmp (Worm.Parite) -> Quarantined and deleted successfully.
C:\Windows\Temp\mke6779.tmp (Worm.Parite) -> Quarantined and deleted successfully.
C:\Windows\Temp\moe8E79.tmp (Worm.Parite) -> Quarantined and deleted successfully.
C:\Windows\Temp\wia55DC.tmp (Worm.Parite) -> Quarantined and deleted successfully.
C:\Windows\Temp\vaa8D6.tmp (Worm.Parite) -> Quarantined and deleted successfully.
C:\Windows\Temp\VRT7898.tmp (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Windows\System32\config\systemprofile\wuaucldt.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\System32\w.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Windows\System32\FInstall.sys (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Windows\System32\opear.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
Is it against policy to use teamviewer?

Is it against policy to use teamviewer?

I don't think that would be of any help at this point.

I'd suggest you disconnect from the internet and keep running MBAM until it's clean.
If you can get to that point, try running Combofix.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI