Page 1 of 6 123 ... LastLast
Results 1 to 10 of 56

Thread: Malware Attack

  1. #1
    Experienced User
    Overall activity: 6.0%

    Join Date
    Aug 2009
    Location
    Bali
    Posts
    577
    Liked
    44 times
    Points
    8,590

    Malware Attack

    Hi, this morning while I browse my facebook account this warning appear to my FF


    The web page was I opened were facebook, raymond, GOTD and imageshack. Is this one of malware attack? What should I do with this?
    The warning is still open, I don't choose OK yet. I want to have suggestions of expert here.
    -------------
    Oke..meanwhile waiting for suggestions, I decide to press OK button and my FF (windows security..? ) did an analyzed and found this:

    I'm quite shock saw that result. Yesterday I did a full scan of my laptop with KIS 2011 and found nothing!Today found this...!
    Is anyone have an experience of this.?
    Thanks in advance.
    Last edited by leofelix; 09-19-2010 at 12:14 AM. Reason: screenoshots changed

  2. #2
    Whiz Kid
    Overall activity: 0%

    Join Date
    Sep 2008
    Location
    Albania
    Posts
    1,771
    Liked
    80 times
    Points
    20,857
    Hmmm...have a look at the title of the warning window. Weird huh? It looks like some web-based rogueware to me. Or your browser has been hijacked. Did you install any toolbar recently?
    Anyways post a HijackThis log here...

    Screw Google! Ask me!


  3. #3
    The Specialist *
    Overall activity: 76.0%

    Join Date
    May 2010
    Location
    KOLKATA
    Posts
    5,162
    Liked
    731 times
    Points
    47,580
    Download Hitman Pro (activate pro if any malware found) & Malwarebytes' Anti-Malware make a full scan. Download HijackThis make a scan post & your log here.
    I don't need to know everything, I just need to know where to find it, when I need it.

  4. #4
    Experienced User
    Overall activity: 6.0%

    Join Date
    Aug 2009
    Location
    Bali
    Posts
    577
    Liked
    44 times
    Points
    8,590
    Here the HijackThis result:
    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 10:30:24 AM, on 9/18/2010
    Platform: Windows 7 (WinNT 6.00.3504)
    MSIE: Internet Explorer v8.00 (8.00.7600.16385)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Windows\system32\igfxsrvc.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
    C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
    C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
    C:\Program Files\AntiLogger\AntiLogger.exe
    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    C:\Users\KAY EXA\Documents\Downloads\Compressed\firefox-ultimate-optimizer-11\Firefox Ultimate Optimizer.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
    C:\Program Files\Internet Download Manager\IDMan.exe
    C:\Program Files\OO Software\DriveLED\oodled.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
    C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
    C:\Program Files\Internet Download Manager\IEMonitor.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtblfs.exe
    C:\Program Files\Windows Live\Mail\wlmail.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
    C:\Program Files\Mozilla Firefox\plugin-container.exe
    C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
    C:\Windows\system32\SearchFilterHost.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://securityresponse.symantec.com/avcenter/fix_homepage/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://securityresponse.symantec.com/avcenter/fix_homepage/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=;ftp=;https=;
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll
    O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
    O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
    O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo Layers Client\YontooIEClient.dll
    O3 - Toolbar: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll
    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
    O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
    O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
    O4 - HKLM\..\Run: [AntiLogger] "C:\Program Files\AntiLogger\AntiLogger.exe" /minimized
    O4 - HKLM\..\Run: [FirefoxUltimateOptimizer] "C:\Users\KAY EXA\Documents\Downloads\Compressed\firefox-ultimate-optimizer-11\Firefox Ultimate Optimizer.exe"
    O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe"
    O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
    O4 - HKCU\..\Run: [DriveLED] C:\Program Files\OO Software\DriveLED\oodled.exe
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized (User 'Default user')
    O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm
    O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
    O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
    O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O9 - Extra button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
    O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
    O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
    O22 - SharedTaskScheduler: Ave's FolderBg - {73526E5A-FD53-4BE7-B5E2-D3C89D7413DC} - C:\Windows\W7FBC\dll.dll
    O23 - Service: Apache2.2 - Apache Software Foundation - c:\xampp\apache\bin\httpd.exe
    O23 - Service: Kaspersky Anti-Virus Service (AVP) - Kaspersky Lab ZAO - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: FsUsbExService - Teruten - C:\Windows\system32\FsUsbExService.Exe
    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    O23 - Service: mysql - Unknown owner - c:\xampp\mysql\bin\mysqld.exe
    O23 - Service: NitroPDFDriverCreatorReadSpool (NitroDriverReadSpool) - Nitro PDF Software - C:\Program Files\Nitro PDF\Professional\NitroPDFDriverService.exe
    O23 - Service: NLS Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\system32\NLSSRV32.EXE
    O23 - Service: O&O DriveLED - O&O Software GmbH - C:\Program Files\OO Software\DriveLED\oodlag.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe
    O23 - Service: @C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
    --
    End of file - 10174 bytes

  5. #5
    Guest
    Overall activity: 54.0%

    Join Date
    May 2007
    Location
    Philippines
    Posts
    4,006
    Liked
    710 times
    Points
    47,645
    Just a scareware page. Anyhow, what is your current browser setting, it is sandboxed?/hardened?/ or run only with default setting. Please check your OS,Java,Adobe Reader if its updated. Run Ccleaner to get rid off some unhealthy cookies. Just kill the browser via task manager, if this happens again.

    Could you please share the suspected link here or just Pm it to me : "hxxp"

    Now, just in case you have installed something ( dropper) from that site, then run an optional MBAM scan.
    "Stars and the Sun"


  6. #6
    Whiz Kid
    Overall activity: 0%

    Join Date
    Sep 2008
    Location
    Albania
    Posts
    1,771
    Liked
    80 times
    Points
    20,857
    Do as ceyfer suggested and remove Vuze toolbar.

  7. #7
    Moderator
    Overall activity: 100.0%

    Join Date
    May 2010
    Location
    Eire /The Garden of Ireland
    Posts
    5,486
    Liked
    1750 times
    Points
    31,018
    Sorry KaYan for been a bit slow to post and it looks like your in good hands with Alboguy and Ceyfer, indeed it looks like scareware, as i have seen similar before, and i was just talking yesterday to a friend of mine as some-one he knows has the exact problem, with the exception he is now locked out of one of his drives.
    please post back if it's not sorted or if it is..
    Stutz Bearcat

  8. #8
    Experienced User
    Overall activity: 6.0%

    Join Date
    Aug 2009
    Location
    Bali
    Posts
    577
    Liked
    44 times
    Points
    8,590
    @cyfer
    My FF is run by default. Add ons I added only WOT, grease monkey, linkification, FEBE, fastestFox and redirect remover. My Java, OS and Adobe reader are up to date.
    What do you mean of "suspected link"?? I got that warning while I opened my facebook account.
    @alboguy
    I uninstalled before this warning showed up..

    ups, forget to ask..
    Should I remove all the detected malwares/virus found by Windows security? Or I cancel it and do MBAM scan??
    Last edited by KaYaN; 09-18-2010 at 11:17 AM.

  9. #9
    Whiz Kid
    Overall activity: 0%

    Join Date
    Sep 2008
    Location
    Albania
    Posts
    1,771
    Liked
    80 times
    Points
    20,857
    KaYan there's no such program like "Windows Security". I told you it's a web-based rogueware or better say scareware. Of course you have to cancel it. And look at the screenshot you just posted.
    WOT is displaying an orange colour. Be more careful KaYan!! Don't miss the details.

  10. #10
    Verified Member
    Overall activity: 0%

    Join Date
    Aug 2009
    Posts
    265
    Liked
    1 times
    Points
    4,976

    Bug

    Kayan it a rogue .
    don't click on any thning just close ur browser .
    when i was surfing then i also hve same problem i click on the remove all then a small file has been downloaded if u run tht file then the rouge will try to install. but i thnk u r protected bcoz u r using kis2011 . if kis2011 don't hve defination for this then its proactive will remove this infection if it is there. norton sonar will detect this warning and remove the infection.
    when i hve the rogue virus at tht time i was using trend micro titanium 2011 it didn't detect this small file but it unauthorised protection tht trend titanium hve stop this rogue to intall in my computer.

    to check the antivirus how much it is effective then click on the remove all and download the file and upload this file in virustotal .com and check has any antivirus detect this rogue.i want to say to u bcoz when i hve one rogue file at tht time only 4 antivirus has defiantion at tht time (dr web, eset, spyware antispyware,panda says suscpicios). then i upload this file after 8 hour then mcafee detect this and AVG,Asquare)

 

 
Page 1 of 6 123 ... LastLast

Similar Threads

  1. How Genuine is Zero day malware/new malware test result?
    By Stranger in forum Spyware/Viruses
    Replies: 11
    Last Post: 11-08-2011, 09:36 AM
  2. Replies: 5
    Last Post: 06-02-2011, 10:55 AM
  3. Converting currency on Google can lead to malware attack
    By INDRANIL in forum Spyware/Viruses
    Replies: 4
    Last Post: 05-21-2011, 11:14 AM
  4. IP attack!!!
    By black2 in forum General Forum
    Replies: 8
    Last Post: 04-05-2008, 12:49 PM

Tags for this Thread

All times are GMT +8. The time now is 09:02 AM.