PDA

View Full Version : Not sure if this malware should be removed



RishR
2013-02-23, 06:29
Hi I hope someone can help me please, I am new to this blog so if I am making a mistake bear with me:).

I recently had a problem which was eventually detected by avast and working with them on their forum I have fixed that problem. However my scans with an older version of spybot have not been picking up anything, so I uninstalled that version went to the safer networking website and downloaded the latest free version available to me.

I just ran a scan with it and it found 51 items somethings I deleted as I knew I could as they were not important and could have been malware
(just to be safe). The other items I have no idea about, so could someone please have a look and tell me what I am dealing with and if I should get rid of them??

Search results from Spybot - Search & Destroy

23/02/2013 04:03:03
Scan took 00:43:50.
51 items found.

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\Rish!!\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\6HBBWEQ9\ia.media-imdb.com\IMDBTEST.sol
Properties.size=0
Properties.md5=D41D8CD98F00B204E9800998ECF8427E

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\Rish!!\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\6HBBWEQ9\s.ytimg.com\soundData.sol
Properties.size=0
Properties.md5=D41D8CD98F00B204E9800998ECF8427E

Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done)
C:\Users\Rish!!\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\6HBBWEQ9\s.ytimg.com\videostats.sol
Properties.size=0
Properties.md5=D41D8CD98F00B204E9800998ECF8427E

Statcounter: [SBI $8E73A7FB] Tracking cookie (Firefox: Rish!! (default)) (Browser: Cookie, nothing done)


Log: [SBI $8E73A7FB] Activity: ntbtlog.txt (File, nothing done)
C:\Windows\ntbtlog.txt
Properties.size=414192
Properties.md5=13107D110A088C51B7A77BC03D18B56C
Properties.filedate=1307232027
Properties.filedatetext=2011-06-05 00:00:26

Log: [SBI $8E73A7FB] Install: Directx.log (File, nothing done)
C:\Windows\Directx.log
Properties.size=26839
Properties.md5=8DEE968479D138627AAC2AA86CE37F10
Properties.filedate=1235886166
Properties.filedatetext=2009-03-01 05:42:45

Log: [SBI $8E73A7FB] Install: setupact.log (File, nothing done)
C:\Windows\setupact.log
Properties.size=62819
Properties.md5=C648AE909B16F17A48E7FD1620E1087B
Properties.filedate=1361101481
Properties.filedatetext=2013-02-17 11:44:41

Log: [SBI $8E73A7FB] Install: setupapi.log (File, nothing done)
C:\Windows\setupapi.log
Properties.size=94
Properties.md5=7DCF473391ED652447DF2C62BE835551
Properties.filedate=1162471672
Properties.filedatetext=2006-11-02 12:47:52

Log: [SBI $8E73A7FB] Install: wmsetup.log (File, nothing done)
C:\Windows\wmsetup.log
Properties.size=562
Properties.md5=39C333401D0FDEC258BFF0864A55882D
Properties.filedate=1275875915
Properties.filedatetext=2010-06-07 01:58:34

Log: [SBI $8E73A7FB] Install: DtcInstall.log (File, nothing done)
C:\Windows\DtcInstall.log
Properties.size=2856
Properties.md5=B27689B2E3780770853BF3EC567E8F9A
Properties.filedate=1229102484
Properties.filedatetext=2008-12-12 17:21:23

Log: [SBI $8E73A7FB] Shutdown: System32\wbem\logs\wmiprov.log (File, nothing done)
C:\Windows\System32\wbem\logs\wmiprov.log
Properties.size=39265
Properties.md5=219B0B20C495F70CEDA53602A0E618DB
Properties.filedate=1361590386
Properties.filedatetext=2013-02-23 03:33:06

Ahead Nero Burning Rom: [SBI $B67505E9] Recent file list (Registry Key, nothing done)
HKEY_USERS\S-1-5-21-2120591977-3353888384-1951892941-1000\Software\Ahead\Nero - Burning Rom\Recent file list

Ahead Nero Burning Rom: [SBI $F3FD92E9] Working directory (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-2120591977-3353888384-1951892941-1000\Software\Ahead\Nero - Burning Rom\Settings\WorkingDir

Internet Explorer: [SBI $1E8157BE] Typed URL list (Registry Key, nothing done)
HKEY_USERS\S-1-5-21-2120591977-3353888384-1951892941-1000\Software\Microsoft\Internet Explorer\TypedURLs

Internet Explorer: [SBI $0BC7B918] User agent (Registry Change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent

Internet Explorer: [SBI $0BC7B918] User agent (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-2120591977-3353888384-1951892941-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent

Internet Explorer: [SBI $0BC7B918] User agent (Registry Change, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent

MS Management Console: [SBI $ECD50EAD] Recent command list (Registry Key, nothing done)
HKEY_USERS\S-1-5-21-2120591977-3353888384-1951892941-1000\Software\Microsoft\Microsoft Management Console\Recent File List

MS Media Player: [SBI $E48560B4] Recent file list (Registry Key, nothing done)
HKEY_USERS\S-1-5-21-2120591977-3353888384-1951892941-1000\Software\Microsoft\MediaPlayer\Player\RecentFileList

MS Media Player: [SBI $735D57D7] Recent open directory (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-2120591977-3353888384-1951892941-1000\Software\Microsoft\MediaPlayer\Player\Settings\OpenDir

MS Media Player: [SBI $3EE69CC3] Save as Directory (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-2120591977-3353888384-1951892941-1000\Software\Microsoft\MediaPlayer\Player\Settings\SaveAsDir

MS Media Player: [SBI $3B9B7B9A] Last CD record path (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-2120591977-3353888384-1951892941-1000\Software\Microsoft\MediaPlayer\Preferences\CDRecordPath

MS Media Player: [SBI $5C51E349] Client ID (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-2120591977-3353888384-1951892941-1000\Software\Microsoft\MediaPlayer\Player\Settings\Client ID

MS Direct3D: [SBI $7FB7B83F] Most recent application (Registry Change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Direct3D\MostRecentApplication\Name

MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Direct3D\MostRecentApplication\Name

MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-2120591977-3353888384-1951892941-1000\Software\Microsoft\Direct3D\MostRecentApplication\Name

MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Direct3D\MostRecentApplication\Name

MS DirectDraw: [SBI $EB49D5AF] Most recent application (Registry Change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication\Name

MS DirectInput: [SBI $9A063C91] Most recent application (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-2120591977-3353888384-1951892941-1000\Software\Microsoft\DirectInput\MostRecentApplication\Name

MS DirectInput: [SBI $7B184199] Most recent application ID (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-2120591977-3353888384-1951892941-1000\Software\Microsoft\DirectInput\MostRecentApplication\Id

MS Paint: [SBI $07867C39] Recent file list (Registry Key, nothing done)
HKEY_USERS\S-1-5-21-2120591977-3353888384-1951892941-1000\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List

MS Wordpad: [SBI $4C02334D] Recent file list (Registry Key, nothing done)
HKEY_USERS\S-1-5-21-2120591977-3353888384-1951892941-1000\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad\Recent File List

Windows: [SBI $1E4E2003] Drivers installation paths (Registry Change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Installation Sources

Windows.OpenWith: [SBI $F7204896] Open with list - .AVI extension (Registry Key, nothing done)
HKEY_USERS\S-1-5-21-2120591977-3353888384-1951892941-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.AVI\OpenWithList

Windows.OpenWith: [SBI $A1C94E79] Open with list - .BMP extension (Registry Key, nothing done)
HKEY_USERS\S-1-5-21-2120591977-3353888384-1951892941-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.BMP\OpenWithList

Windows.OpenWith: [SBI $9E8D5C8A] Open with list - .CDA extension (Registry Key, nothing done)
HKEY_USERS\S-1-5-21-2120591977-3353888384-1951892941-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CDA\OpenWithList

Windows Explorer: [SBI $A2C7B3CD] Recent wallpaper list (Registry Key, nothing done)
HKEY_USERS\S-1-5-21-2120591977-3353888384-1951892941-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Wallpaper\MRU

Windows Explorer: [SBI $2026AFB6] User Assistant history IE (Registry Key, nothing done)
HKEY_USERS\S-1-5-21-2120591977-3353888384-1951892941-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count

Windows Explorer: [SBI $6107D172] User Assistant history files (Registry Key, nothing done)
HKEY_USERS\S-1-5-21-2120591977-3353888384-1951892941-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count

Windows Media SDK: [SBI $37AAEDE6] Computer name (Registry Change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows Media\WMSDK\General\ComputerName

Windows Media SDK: [SBI $37AAEDE6] Computer name (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-2120591977-3353888384-1951892941-1000\Software\Microsoft\Windows Media\WMSDK\General\ComputerName

Windows Media SDK: [SBI $37AAEDE6] Computer name (Registry Change, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows Media\WMSDK\General\ComputerName

Windows Media SDK: [SBI $CAA58B6E] Unique ID (Registry Change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows Media\WMSDK\General\UniqueID

Windows Media SDK: [SBI $CAA58B6E] Unique ID (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-2120591977-3353888384-1951892941-1000\Software\Microsoft\Windows Media\WMSDK\General\UniqueID

Windows Media SDK: [SBI $CAA58B6E] Unique ID (Registry Change, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows Media\WMSDK\General\UniqueID

Windows Media SDK: [SBI $BACCD0DA] Volume serial number (Registry Value, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows Media\WMSDK\General\VolumeSerialNumber

Windows Media SDK: [SBI $BACCD0DA] Volume serial number (Registry Value, nothing done)
HKEY_USERS\S-1-5-21-2120591977-3353888384-1951892941-1000\Software\Microsoft\Windows Media\WMSDK\General\VolumeSerialNumber

Windows Media SDK: [SBI $BACCD0DA] Volume serial number (Registry Value, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows Media\WMSDK\General\VolumeSerialNumber

Cookie: [SBI $49804B54] Browser: Cookie (1) (Browser: Cookie, nothing done)


History: [SBI $49804B54] Browser: History (3) (Browser: History, nothing done)


Cookie: [SBI $49804B54] Browser: Cookie (68) (Browser: Cookie, nothing done)



--- Spybot - Search & Destroy version: 2.0.12.131 DLL (build: 20121113) ---

2012-11-13 blindman.exe (2.0.12.151)
2012-11-13 explorer.exe (2.0.12.173)
2012-11-13 SDBootCD.exe (2.0.12.109)
2012-11-13 SDCleaner.exe (2.0.12.110)
2012-11-13 SDDelFile.exe (2.0.12.94)
2012-11-13 SDFiles.exe (2.0.12.135)
2012-11-13 SDFileScanHelper.exe (2.0.12.1)
2012-11-13 SDFSSvc.exe (2.0.12.205)
2012-11-13 SDImmunize.exe (2.0.12.130)
2012-11-13 SDLogReport.exe (2.0.12.107)
2012-11-13 SDPESetup.exe (2.0.12.3)
2012-11-13 SDPEStart.exe (2.0.12.86)
2012-11-13 SDPhoneScan.exe (2.0.12.27)
2012-11-13 SDPRE.exe (2.0.12.13)
2012-11-13 SDPrepPos.exe (2.0.12.10)
2012-11-13 SDQuarantine.exe (2.0.12.103)
2012-11-13 SDRootAlyzer.exe (2.0.12.116)
2012-11-13 SDSBIEdit.exe (2.0.12.39)
2012-11-13 SDScan.exe (2.0.12.173)
2012-11-13 SDScript.exe (2.0.12.53)
2012-11-13 SDSettings.exe (2.0.12.130)
2012-11-13 SDShred.exe (2.0.12.105)
2012-11-13 SDSysRepair.exe (2.0.12.101)
2012-11-13 SDTools.exe (2.0.12.150)
2012-11-13 SDTray.exe (2.0.12.127)
2012-11-13 SDUpdate.exe (2.0.12.89)
2012-11-13 SDUpdSvc.exe (2.0.12.76)
2012-11-13 SDWelcome.exe (2.0.12.126)
2012-11-13 SDWSCSvc.exe (2.0.12.2)
2013-02-22 unins000.exe (51.1052.0.0)
1999-12-02 xcacls.exe
2012-08-23 borlndmm.dll (10.0.2288.42451)
2012-09-05 DelZip190.dll (1.9.0.107)
2012-09-10 libeay32.dll (1.0.0.4)
2012-09-10 libssl32.dll (1.0.0.4)
2012-11-13 SDAdvancedCheckLibrary.dll (2.0.12.98)
2012-11-13 SDECon32.dll (2.0.12.113)
2012-11-13 SDEvents.dll (2.0.12.2)
2012-11-13 SDFileScanLibrary.dll (2.0.12.9)
2012-11-13 SDHelper.dll (2.0.12.88)
2012-11-13 SDImmunizeLibrary.dll (2.0.12.2)
2012-11-13 SDLists.dll (2.0.12.4)
2012-11-13 SDResources.dll (2.0.12.7)
2012-11-13 SDScanLibrary.dll (2.0.12.131)
2012-11-13 SDTasks.dll (2.0.12.15)
2012-11-13 SDWinLogon.dll (2.0.12.0)
2012-08-23 sqlite3.dll
2012-09-10 ssleay32.dll (1.0.0.4)
2012-11-13 Tools.dll (2.0.12.36)
2012-11-13 UninsSrv.dll (2.0.12.52)
2012-11-14 Includes\Adware.sbi (*)
2012-11-14 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2012-11-14 Includes\Dialer.sbi (*)
2012-11-14 Includes\DialerC.sbi (*)
2012-11-14 Includes\HeavyDuty.sbi (*)
2012-11-14 Includes\Hijackers.sbi (*)
2012-11-14 Includes\HijackersC.sbi (*)
2012-11-14 Includes\iPhone.sbi (*)
2012-11-14 Includes\Keyloggers.sbi (*)
2012-11-14 Includes\KeyloggersC.sbi (*)
2012-11-14 Includes\Malware.sbi (*)
2012-11-14 Includes\MalwareC.sbi (*)
2012-11-14 Includes\PUPS.sbi (*)
2012-11-14 Includes\PUPSC.sbi (*)
2012-11-14 Includes\Security.sbi (*)
2012-11-14 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2012-11-14 Includes\Spyware.sbi (*)
2012-11-14 Includes\SpywareC.sbi (*)
2011-06-07 Includes\Tracks.sbi (*)
2005-02-17 Includes\Tracks.uti (*)
2012-11-14 Includes\Trojans.sbi (*)
2012-11-14 Includes\TrojansC-02.sbi (*)
2012-11-14 Includes\TrojansC-03.sbi (*)
2012-11-14 Includes\TrojansC-04.sbi (*)
2012-11-14 Includes\TrojansC-05.sbi (*)
2012-11-14 Includes\TrojansC.sbi (*)

:thanks: in advance.

Rish

Zenobia
2013-02-23, 09:21
One is a tracking cookie,and the rest are all just tracks.
There's a description of tracks here:
http://www.safer-networking.org/faq/usage-tracks/
If anything comes up in a scan you're unsure about,if you click on it,over to the left it will show you what category it is in,also. :)

If you read the description above you can decide if you would like Spybot to keep scanning for Tracks.If you would rather it didn't,you can doubleclick Spybot-S&D Start Center,checkmark Advanced User Mode,then click Settings.If you have an operating system with User Account Control,you should be prompted by it,please click Yes.
After Settings opens,click the Categories tab,rightclick somewhere in the window,and select Spyware scan only,then click Apply and OK.

RishR
2013-02-23, 10:43
Hi Zenobia,

In your opinion do you think its is better to remove these tracks:confused:

But :thanks: for getting back to me so quickly.

Rish

Zenobia
2013-02-23, 11:59
You're welcome. :)
It's totally up to you.I scan for tracks myself every so often.While the description is true in the link I posted above:

This information is useful as it can speed up access to data.
,I like the side effect that scanning for tracks clears up a bit of clutter,mainly.
That's just my personal preference,though.I've always viewed scanning for and fixing tracks as kind of an optional thing.

You could decide not to scan for tracks,if you wish.
Or,where tracks are new to you,you could keep scanning for tracks,and anything you're unsure about letting Spybot remove,you can uncheck,and Spybot won't fix it when you hit Fix Selected,if you're more comfortable with that at first. :)

RishR
2013-02-24, 06:30
Thank you for getting back to me so quickly:D:, Well I have deleted some tracks and others have been quarantined automatically. I think I will be fine with tracks from now on anyway.

However, I just commenced a root skit scan, the quick scan said there are signs of root kits and I started a deeper scan. Would you mind taking a look to see if these files are malware hiding a something else.

// info: Rootkit removal help file
// copyright: (c) 2008-2013 Safer-Networking Ltd. All rights reserved.

:: RootAlyzer Results
File:"No admin in ACL","C:\Users\All Users\Real\setup\config.ini"
File:"No admin in ACL","C:\Users\All Users\Microsoft\OFFICE\DATA"
File:"No admin in ACL","C:\Users\All Users\Microsoft\OFFICE\DATA\OPA12.BAK"
File:"No admin in ACL","C:\Users\All Users\Microsoft\OFFICE\DATA\opa12.dat"
File:"No admin in ACL","C:\ProgramData\Real\setup\config.ini"
File:"No admin in ACL","C:\ProgramData\Microsoft\OFFICE\DATA"

I uninstalled Real Player a long time ago but I still see the icon in my Auto play options, should I delete them?

Hope you can help with this

Rishi

Zenobia
2013-02-24, 12:43
Things found in the rootkit scan aren't necessarily bad.This page helps to explain that:
http://www.safer-networking.org/faq/are-the-found-items-really-rootkits/
I believe what was found in your scan is nothing bad,but as for taking a look to see if the files are malware hiding as something else,sorry I can't.That's more a Team Spybot territory question. :)
In the link I posted above,it says if there is anything you're unsure about to ask for help in the RootAlyzer Forum,so you could ask about your scan results in there:
http://forums.spybot.info/forumdisplay.php?f=46

RishR
2013-02-24, 14:06
:thanks: for all your help Zenobia

Rish

Zenobia
2013-02-25, 04:30
You're welcome. :)