about 2-3 days ago, I use remote access (via TeamViewer) to remotely repair my friend's laptop, after that, my pc is
running a bit slow, and detected several virus trojan, later I know it;s infected from my friend's laptop. Then, I scan
(full scan) my PC with Comodo Internet Security premium (detected 106 threats), Emsisoft antimalware, Malwarebytes.. now,
Malwarebyte only show 1 virus but still exist even after reboot my computer.
Even my PC is now running fine, but, I'm still worried since this PC is full of my father's work inside
please help me, I'm in panic right now..
Okay this is all log reports:
Malwarebytes Anti-Malware (PRO) 1.60.1.1000
www.malwarebytes.org
Database version: v2012.04.03.09
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Razhar :: RAZHAR-PC [administrator]
Protection: Enabled
04/04/2012 1:58:55
mbam-log-2012-04-04 (01-58-55).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 205922
Time elapsed: 7 minute(s), 11 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|15354 (Trojan.Agent) -> Data: C:
\PROGRA~3\LOCALS~1\Temp\msaeod.cmd -> Delete on reboot.
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
This is the virus (registry?) that still persist even after restart that I mentioned before.
When I open (double click) the GMER it automatically run scan, then less than 10seconds, it just stop scan and doesn't
generate any report. Then I manually click scan, and this is the result:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-04-04 02:28:56
Windows 6.1.7601 Service Pack 1
Running: gmer.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\68a3c4cbf2bc
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\68a3c4cbf2bc@8c541d98ca90
0x3B 0xDC 0xE4 0x82 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\68a3c4cbf2bc (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\68a3c4cbf2bc@8c541d98ca90
0x3B 0xDC 0xE4 0x82 ...
---- Files - GMER 1.0.15 ----
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\952D5E36-272D-4943-8101-EC0B24BEEBB8.data.info
250 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\05B83C1F-F0B5-422F-8185-0576A3586DA6.data
25911874 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\05B83C1F-F0B5-422F-8185-0576A3586DA6.data.info
272 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\376E1F02-D011-40B8-A490-CD9C9262C69F.data
607260 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\376E1F02-D011-40B8-A490-CD9C9262C69F.data.info
112 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\41E13CAD-D35A-4FC2-B08E-B3CC8B944F92.data
39198432 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\41E13CAD-D35A-4FC2-B08E-B3CC8B944F92.data.info
160 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\42392354-93DE-4028-B43D-B14BA876AB02.data
92216 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\42392354-93DE-4028-B43D-B14BA876AB02.data.info
260 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\4809DADA-E877-4D56-8818-324BB274A310.data
557765 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\4809DADA-E877-4D56-8818-324BB274A310.data.info
182 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\48542729-D1B6-48C6-BA1B-98A8C4C64ACA.data
25911874 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\48542729-D1B6-48C6-BA1B-98A8C4C64ACA.data.info
172 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\5C003F49-1CD1-423A-9F54-BF00DB28144F.data
32561152 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\5C003F49-1CD1-423A-9F54-BF00DB28144F.data.info
198 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\622D9A4E-ECF8-4B3E-9818-1FE726C45E15.data
92216 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\622D9A4E-ECF8-4B3E-9818-1FE726C45E15.data.info
250 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\952D5E36-272D-4943-8101-EC0B24BEEBB8.data
92216 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\DB7B2DEF-6D46-49B3-94B5-B1E51A1E59AA.data
4107248 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\DB7B2DEF-6D46-49B3-94B5-B1E51A1E59AA.data.info
272 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\E38E15E9-EA74-4A09-9227-D8E99F61E597.data
92216 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\E38E15E9-EA74-4A09-9227-D8E99F61E597.data.info
250 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\E4679DB6-663F-4992-9923-234CF7C81E91.data
7974400 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\E4679DB6-663F-4992-9923-234CF7C81E91.data.info
214 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\E808217F-7EC4-4638-A5D2-A2D9B6752BF6.data
92216 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\E808217F-7EC4-4638-A5D2-A2D9B6752BF6.data.info
250 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\F547578D-D381-4216-ACF9-35F2829DE49C.data
3417496 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\F547578D-D381-4216-ACF9-35F2829DE49C.data.info
174 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\Temp
0 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\Temp\baseupd
0 bytes
File C:\System Volume Information\SystemRestore\FRStaging\Users\Razhar\Downloads\Anime Lyrics dot Com - Kugutsu Uta--Ura
Mite Chiru - The Ballade of Puppets Flowers Grieve and Fall - Ghost in the Shell; Ghost in the Shell Stand Alone Complex;
Koukaku Kidoutai latin - Anime_files\AL-W1IzU3RT.js 169248 bytes
File C:\System Volume Information\SystemRestore\FRStaging\Users\Razhar\Downloads\Anime Lyrics dot Com - Kugutsu Uta--Ura
Mite Chiru - The Ballade of Puppets Flowers Grieve and Fall - Ghost in the Shell; Ghost in the Shell Stand Alone Complex;
Koukaku Kidoutai latin - Anime_files\alcom.js 4094 bytes
File C:\System Volume Information\SystemRestore\FRStaging\Users\Razhar\Downloads\Anime Lyrics dot Com - Kugutsu Uta--Ura
Mite Chiru - The Ballade of Puppets Flowers Grieve and Fall - Ghost in the Shell; Ghost in the Shell Stand Alone Complex;
Koukaku Kidoutai latin - Anime_files\all.js 149557 bytes
File C:\System Volume Information\SystemRestore\FRStaging\Users\Razhar\Downloads\Anime Lyrics dot Com - Kugutsu Uta--Ura
Mite Chiru - The Ballade of Puppets Flowers Grieve and Fall - Ghost in the Shell; Ghost in the Shell Stand Alone Complex;
Koukaku Kidoutai latin - Anime_files\quant.js 5299 bytes
File C:\System Volume Information\SystemRestore\FRStaging\Users\Razhar\Downloads\Anime Lyrics dot Com - Kugutsu Uta--Ura
Mite Chiru - The Ballade of Puppets Flowers Grieve and Fall - Ghost in the Shell; Ghost in the Shell Stand Alone Complex;
Koukaku Kidoutai latin - Anime_files\show_ads.js 13115 bytes
File C:\System Volume Information\SystemRestore\FRStaging\Users\Razhar\Downloads\Anime Lyrics dot Com - Kugutsu Uta--Ura
Mite Chiru - The Ballade of Puppets Flowers Grieve and Fall - Ghost in the Shell; Ghost in the Shell Stand Alone Complex;
Koukaku Kidoutai latin - Anime_files\supernote.js 7378 bytes
File C:\System Volume Information\SystemRestore\FRStaging\Users\Razhar\Downloads\Anime Lyrics dot Com - Kugutsu Uta--Ura
Mite Chiru - The Ballade of Puppets Flowers Grieve and Fall - Ghost in the Shell; Ghost in the Shell Stand Alone Complex;
Koukaku Kidoutai latin - Anime_files\swfobject.js 6880 bytes
File C:\System Volume Information\SystemRestore\FRStaging\Users\Razhar\Downloads\Anime Lyrics dot Com - Kugutsu Uta--Ura
Mite Chiru - The Ballade of Puppets Flowers Grieve and Fall - Ghost in the Shell; Ghost in the Shell Stand Alone Complex;
Koukaku Kidoutai latin - Anime_files\urchin.js 22678 bytes
---- EOF - GMER 1.0.15 ----
running a bit slow, and detected several virus trojan, later I know it;s infected from my friend's laptop. Then, I scan
(full scan) my PC with Comodo Internet Security premium (detected 106 threats), Emsisoft antimalware, Malwarebytes.. now,
Malwarebyte only show 1 virus but still exist even after reboot my computer.
Even my PC is now running fine, but, I'm still worried since this PC is full of my father's work inside
please help me, I'm in panic right now..
Okay this is all log reports:
Malwarebytes Anti-Malware (PRO) 1.60.1.1000
www.malwarebytes.org
Database version: v2012.04.03.09
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Razhar :: RAZHAR-PC [administrator]
Protection: Enabled
04/04/2012 1:58:55
mbam-log-2012-04-04 (01-58-55).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 205922
Time elapsed: 7 minute(s), 11 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|15354 (Trojan.Agent) -> Data: C:
\PROGRA~3\LOCALS~1\Temp\msaeod.cmd -> Delete on reboot.
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
This is the virus (registry?) that still persist even after restart that I mentioned before.
When I open (double click) the GMER it automatically run scan, then less than 10seconds, it just stop scan and doesn't
generate any report. Then I manually click scan, and this is the result:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-04-04 02:28:56
Windows 6.1.7601 Service Pack 1
Running: gmer.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\68a3c4cbf2bc
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\68a3c4cbf2bc@8c541d98ca90
0x3B 0xDC 0xE4 0x82 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\68a3c4cbf2bc (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\68a3c4cbf2bc@8c541d98ca90
0x3B 0xDC 0xE4 0x82 ...
---- Files - GMER 1.0.15 ----
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\952D5E36-272D-4943-8101-EC0B24BEEBB8.data.info
250 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\05B83C1F-F0B5-422F-8185-0576A3586DA6.data
25911874 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\05B83C1F-F0B5-422F-8185-0576A3586DA6.data.info
272 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\376E1F02-D011-40B8-A490-CD9C9262C69F.data
607260 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\376E1F02-D011-40B8-A490-CD9C9262C69F.data.info
112 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\41E13CAD-D35A-4FC2-B08E-B3CC8B944F92.data
39198432 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\41E13CAD-D35A-4FC2-B08E-B3CC8B944F92.data.info
160 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\42392354-93DE-4028-B43D-B14BA876AB02.data
92216 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\42392354-93DE-4028-B43D-B14BA876AB02.data.info
260 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\4809DADA-E877-4D56-8818-324BB274A310.data
557765 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\4809DADA-E877-4D56-8818-324BB274A310.data.info
182 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\48542729-D1B6-48C6-BA1B-98A8C4C64ACA.data
25911874 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\48542729-D1B6-48C6-BA1B-98A8C4C64ACA.data.info
172 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\5C003F49-1CD1-423A-9F54-BF00DB28144F.data
32561152 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\5C003F49-1CD1-423A-9F54-BF00DB28144F.data.info
198 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\622D9A4E-ECF8-4B3E-9818-1FE726C45E15.data
92216 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\622D9A4E-ECF8-4B3E-9818-1FE726C45E15.data.info
250 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\952D5E36-272D-4943-8101-EC0B24BEEBB8.data
92216 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\DB7B2DEF-6D46-49B3-94B5-B1E51A1E59AA.data
4107248 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\DB7B2DEF-6D46-49B3-94B5-B1E51A1E59AA.data.info
272 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\E38E15E9-EA74-4A09-9227-D8E99F61E597.data
92216 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\E38E15E9-EA74-4A09-9227-D8E99F61E597.data.info
250 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\E4679DB6-663F-4992-9923-234CF7C81E91.data
7974400 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\E4679DB6-663F-4992-9923-234CF7C81E91.data.info
214 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\E808217F-7EC4-4638-A5D2-A2D9B6752BF6.data
92216 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\E808217F-7EC4-4638-A5D2-A2D9B6752BF6.data.info
250 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\F547578D-D381-4216-ACF9-35F2829DE49C.data
3417496 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\F547578D-D381-4216-ACF9-35F2829DE49C.data.info
174 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\Temp
0 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\Temp\baseupd
0 bytes
File C:\System Volume Information\SystemRestore\FRStaging\Users\Razhar\Downloads\Anime Lyrics dot Com - Kugutsu Uta--Ura
Mite Chiru - The Ballade of Puppets Flowers Grieve and Fall - Ghost in the Shell; Ghost in the Shell Stand Alone Complex;
Koukaku Kidoutai latin - Anime_files\AL-W1IzU3RT.js 169248 bytes
File C:\System Volume Information\SystemRestore\FRStaging\Users\Razhar\Downloads\Anime Lyrics dot Com - Kugutsu Uta--Ura
Mite Chiru - The Ballade of Puppets Flowers Grieve and Fall - Ghost in the Shell; Ghost in the Shell Stand Alone Complex;
Koukaku Kidoutai latin - Anime_files\alcom.js 4094 bytes
File C:\System Volume Information\SystemRestore\FRStaging\Users\Razhar\Downloads\Anime Lyrics dot Com - Kugutsu Uta--Ura
Mite Chiru - The Ballade of Puppets Flowers Grieve and Fall - Ghost in the Shell; Ghost in the Shell Stand Alone Complex;
Koukaku Kidoutai latin - Anime_files\all.js 149557 bytes
File C:\System Volume Information\SystemRestore\FRStaging\Users\Razhar\Downloads\Anime Lyrics dot Com - Kugutsu Uta--Ura
Mite Chiru - The Ballade of Puppets Flowers Grieve and Fall - Ghost in the Shell; Ghost in the Shell Stand Alone Complex;
Koukaku Kidoutai latin - Anime_files\quant.js 5299 bytes
File C:\System Volume Information\SystemRestore\FRStaging\Users\Razhar\Downloads\Anime Lyrics dot Com - Kugutsu Uta--Ura
Mite Chiru - The Ballade of Puppets Flowers Grieve and Fall - Ghost in the Shell; Ghost in the Shell Stand Alone Complex;
Koukaku Kidoutai latin - Anime_files\show_ads.js 13115 bytes
File C:\System Volume Information\SystemRestore\FRStaging\Users\Razhar\Downloads\Anime Lyrics dot Com - Kugutsu Uta--Ura
Mite Chiru - The Ballade of Puppets Flowers Grieve and Fall - Ghost in the Shell; Ghost in the Shell Stand Alone Complex;
Koukaku Kidoutai latin - Anime_files\supernote.js 7378 bytes
File C:\System Volume Information\SystemRestore\FRStaging\Users\Razhar\Downloads\Anime Lyrics dot Com - Kugutsu Uta--Ura
Mite Chiru - The Ballade of Puppets Flowers Grieve and Fall - Ghost in the Shell; Ghost in the Shell Stand Alone Complex;
Koukaku Kidoutai latin - Anime_files\swfobject.js 6880 bytes
File C:\System Volume Information\SystemRestore\FRStaging\Users\Razhar\Downloads\Anime Lyrics dot Com - Kugutsu Uta--Ura
Mite Chiru - The Ballade of Puppets Flowers Grieve and Fall - Ghost in the Shell; Ghost in the Shell Stand Alone Complex;
Koukaku Kidoutai latin - Anime_files\urchin.js 22678 bytes
---- EOF - GMER 1.0.15 ----