Argus
2007-04-30, 12:05
Hi, I have been trying to run a full scan with spybot, and spybot gets as far as detecting smitfraud C, mediamotor, Sgrunt, Coolwebsearch, and guardian monitor, and then crashes.
The first time, I left the computer for a bit, (as you do, whilst scanning), and came back to find a "windows has shut down this program to protect your computer" message. I put spybot in the DEP ignore list, and tried again.
Again, spybot crashed, no error message from windows or anything, it just disappeared. :(
I tried a third time, with the same result. This time, however I had the foresight to save spybot's scan report before it crashed, but also before it has completed the scan, so it may be missing the vital detection which is causing the crash.
That said, I do not really believe that there is an infection of any kind, but it may of course be possible. I have read about the fp involving guardian monitor, which is one of the things detected. However, the fact that spybot cannot complete a scan has me a leetle worried.
Anyway, here is as much of the report as I was able to save. I have included the entire log in the attachment. Thanks.
--- Search result list ---
Sgrunt: User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-606747145-1343024091-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\sgrunt.biz\*!=W=4
CoolWWWSearch.BadZoneMap: Settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-606747145-1343024091-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ysbweb.com\*!=W=4
CoolWWWSearch.BadZoneMap: Settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-606747145-1343024091-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.net\*!=W=4
MediaMotor: User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-606747145-1343024091-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\elitemediagroup.net\*!=W=4
MediaMotor: User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-606747145-1343024091-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\media-motor.net\*!=W=4
MediaMotor: User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-606747145-1343024091-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mmohsix.com\*!=W=4
Smitfraud-C.: Settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-606747145-1343024091-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\asdbiz.biz\*!=W=4
Smitfraud-C.: User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-606747145-1343024091-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\greg-tut.com\*!=W=4
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{0E34D615-66A0-11D4-AB49-00105A6F87AB}
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{26FA5DE7-1C96-11D3-9CA6-00500411B995}
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{64CCFDB7-6428-11D3-A957-00105A6F87AB}
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{6A4B26F5-14D0-11D3-9C9A-00500411B995}
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{6B50EFC4-F324-11D2-9C6B-00500411B995}
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{6E6520E9-13F1-11D3-9C98-00500411B995}
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{7C801DCD-ECC8-11D2-9C5C-00500411B995}
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{94D298C9-B76D-11D3-AA25-00105A6F87AB}
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{E38F2E7A-A621-11D3-9CBA-00500411B995}
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.dxStrings
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{64CCFDB7-6428-11D3-A957-00105A6F87AB}
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.dxStrings.1
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.dxTreeList
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.dxTreeList.2
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{7C801DCD-ECC8-11D2-9C5C-00500411B995}
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.dxTreeLocalizer
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0E34D615-66A0-11D4-AB49-00105A6F87AB}
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.dxTreeLocalizer.1
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.xATLBand
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{6E6520E9-13F1-11D3-9C98-00500411B995}
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.xATLBand.1
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.xATLColumn
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{6A4B26F5-14D0-11D3-9C9A-00500411B995}
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.xATLColumn.1
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.xATLOptions
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{E38F2E7A-A621-11D3-9CBA-00500411B995}
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.xATLOptions.1
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.xATLRowStyle
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{94D298C9-B76D-11D3-AA25-00105A6F87AB}
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.xATLRowStyle.1
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.xATLTreeNode
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{26FA5DE7-1C96-11D3-9CA6-00500411B995}
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.xATLTreeNode.1
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.xTransferObject
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.xTransferObject.1
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{6B50EFC4-F324-11D2-9C6B-00500411B995}
XPreload: User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-606747145-1343024091-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\sxload.com\*!=W=4
--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---
2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2006-11-24 TeaTimer.exe (1.5.0.0)
2005-05-31 TeaTimer_original.exe (1.4.0.2)
2007-02-14 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2007-04-18 advcheck.dll (1.5.1.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2007-01-02 Tools.dll (2.0.1.0)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2007-04-04 Includes\Beta.sbi (*)
2005-02-16 Includes\Beta.uti (*)
2007-04-25 Includes\Cookies.sbi (*)
2006-12-08 Includes\Dialer.sbi (*)
2007-04-25 Includes\DialerC.sbi (*)
2007-04-04 Includes\Hijackers.sbi (*)
2007-04-25 Includes\HijackersC.sbi (*)
2006-10-27 Includes\Keyloggers.sbi (*)
2007-04-25 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2007-03-21 Includes\Malware.sbi (*)
2007-04-25 Includes\MalwareC.sbi (*)
2007-03-21 Includes\PUPS.sbi (*)
2007-04-25 Includes\PUPSC.sbi (*)
2007-04-25 Includes\Revision.sbi (*)
2006-12-08 Includes\Security.sbi (*)
2007-04-25 Includes\SecurityC.sbi (*)
2007-03-21 Includes\Spybots.sbi (*)
2007-04-25 Includes\SpybotsC.sbi (*)
2005-02-17 Includes\Tracks.uti (*)
2007-04-25 Includes\Trojans.sbi (*)
2007-04-25 Includes\TrojansC.sbi (*)
The first time, I left the computer for a bit, (as you do, whilst scanning), and came back to find a "windows has shut down this program to protect your computer" message. I put spybot in the DEP ignore list, and tried again.
Again, spybot crashed, no error message from windows or anything, it just disappeared. :(
I tried a third time, with the same result. This time, however I had the foresight to save spybot's scan report before it crashed, but also before it has completed the scan, so it may be missing the vital detection which is causing the crash.
That said, I do not really believe that there is an infection of any kind, but it may of course be possible. I have read about the fp involving guardian monitor, which is one of the things detected. However, the fact that spybot cannot complete a scan has me a leetle worried.
Anyway, here is as much of the report as I was able to save. I have included the entire log in the attachment. Thanks.
--- Search result list ---
Sgrunt: User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-606747145-1343024091-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\sgrunt.biz\*!=W=4
CoolWWWSearch.BadZoneMap: Settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-606747145-1343024091-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ysbweb.com\*!=W=4
CoolWWWSearch.BadZoneMap: Settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-606747145-1343024091-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.net\*!=W=4
MediaMotor: User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-606747145-1343024091-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\elitemediagroup.net\*!=W=4
MediaMotor: User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-606747145-1343024091-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\media-motor.net\*!=W=4
MediaMotor: User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-606747145-1343024091-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mmohsix.com\*!=W=4
Smitfraud-C.: Settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-606747145-1343024091-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\asdbiz.biz\*!=W=4
Smitfraud-C.: User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-606747145-1343024091-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\greg-tut.com\*!=W=4
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{0E34D615-66A0-11D4-AB49-00105A6F87AB}
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{26FA5DE7-1C96-11D3-9CA6-00500411B995}
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{64CCFDB7-6428-11D3-A957-00105A6F87AB}
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{6A4B26F5-14D0-11D3-9C9A-00500411B995}
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{6B50EFC4-F324-11D2-9C6B-00500411B995}
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{6E6520E9-13F1-11D3-9C98-00500411B995}
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{7C801DCD-ECC8-11D2-9C5C-00500411B995}
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{94D298C9-B76D-11D3-AA25-00105A6F87AB}
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{E38F2E7A-A621-11D3-9CBA-00500411B995}
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.dxStrings
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{64CCFDB7-6428-11D3-A957-00105A6F87AB}
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.dxStrings.1
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.dxTreeList
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.dxTreeList.2
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{7C801DCD-ECC8-11D2-9C5C-00500411B995}
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.dxTreeLocalizer
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0E34D615-66A0-11D4-AB49-00105A6F87AB}
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.dxTreeLocalizer.1
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.xATLBand
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{6E6520E9-13F1-11D3-9C98-00500411B995}
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.xATLBand.1
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.xATLColumn
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{6A4B26F5-14D0-11D3-9C9A-00500411B995}
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.xATLColumn.1
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.xATLOptions
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{E38F2E7A-A621-11D3-9CBA-00500411B995}
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.xATLOptions.1
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.xATLRowStyle
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{94D298C9-B76D-11D3-AA25-00105A6F87AB}
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.xATLRowStyle.1
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.xATLTreeNode
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{26FA5DE7-1C96-11D3-9CA6-00500411B995}
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.xATLTreeNode.1
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.xTransferObject
GuardianMonitor: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\TreeList.xTransferObject.1
GuardianMonitor: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{6B50EFC4-F324-11D2-9C6B-00500411B995}
XPreload: User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-606747145-1343024091-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\sxload.com\*!=W=4
--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---
2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2006-11-24 TeaTimer.exe (1.5.0.0)
2005-05-31 TeaTimer_original.exe (1.4.0.2)
2007-02-14 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2007-04-18 advcheck.dll (1.5.1.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2007-01-02 Tools.dll (2.0.1.0)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2007-04-04 Includes\Beta.sbi (*)
2005-02-16 Includes\Beta.uti (*)
2007-04-25 Includes\Cookies.sbi (*)
2006-12-08 Includes\Dialer.sbi (*)
2007-04-25 Includes\DialerC.sbi (*)
2007-04-04 Includes\Hijackers.sbi (*)
2007-04-25 Includes\HijackersC.sbi (*)
2006-10-27 Includes\Keyloggers.sbi (*)
2007-04-25 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2007-03-21 Includes\Malware.sbi (*)
2007-04-25 Includes\MalwareC.sbi (*)
2007-03-21 Includes\PUPS.sbi (*)
2007-04-25 Includes\PUPSC.sbi (*)
2007-04-25 Includes\Revision.sbi (*)
2006-12-08 Includes\Security.sbi (*)
2007-04-25 Includes\SecurityC.sbi (*)
2007-03-21 Includes\Spybots.sbi (*)
2007-04-25 Includes\SpybotsC.sbi (*)
2005-02-17 Includes\Tracks.uti (*)
2007-04-25 Includes\Trojans.sbi (*)
2007-04-25 Includes\TrojansC.sbi (*)