Results 1 to 2 of 2

Thread: [Win32agend.ieu & Win32FraudLoad.edt] Cannot remove

  1. #1
    Junior Member
    Join Date
    Jan 2010
    Posts
    2

    Default [Win32agend.ieu & Win32FraudLoad.edt] Cannot remove

    Hi Folks.

    Yesterday I got a notification from Windows Defender that a Malware have been detected (TrojanDownloaderWin32/Renos.JM) and send to quarantine. Later Panda CloudAntivirus deleted "Qh1.exe" from the quarantine folder of defender (named it as "Xor-encoded.A")

    I also found a Qh1.exe and Qh0.exe in my Temp-Folder and Autostart entries to the Qh1.exe named "BMIMZMHMFM" But I could delete those easily. I tried to get some info about these .exe-files but google couldn't really help me.

    This Morning I ran SpyBot to check if there was anything left and discovered (besides some cookies) The Malware "Win32agend.ieu" SP removed it but on the next check it appeared again including "Win32FraudLoad.edt"
    I tried RootAlyzer but it didn't found anything. (but it finished the Deep Scan in less than 2 min for the whole PC and Registry. Normal?)

    I must admit I haven't experienced any strange behavior jet (except of the autostart-entries) And I'm trying to block all Internet traffic from unknown programs using "Win 7 Firewall Control" but no strange program appeared by now.

    Please let me know if you need more information to tell me how to get rid of this. Or am I just paranoid?

    The HijackThis Log:
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 13:02:08, on 30.01.2010
    Platform: Unknown Windows (WinNT 6.01.3504)
    MSIE: Internet Explorer v8.00 (8.00.7600.16385)
    Boot mode: Normal

    Running processes:
    D:\System\Panda Cloud Antivirus\PSUNMain.exe
    D:\Internet\Digsby\App\lib\digsby-app.exe
    D:\Music\CD Art Display\CAD.exe
    D:\Music\iTunes\iTunes.exe
    D:\Music\Last.fm\LastFM.exe
    D:\Internet\Digsby\App\lib\aspell\bin\aspell.exe
    D:\Tools\Spybot - Search & Destroy\SpybotSD.exe
    D:\Tools\Spybot - Search & Destroy\TeaTimer.exe
    D:\Internet\Mozilla Firefox\firefox.exe
    C:\Users\JlB\Desktop\RootAlyzer.exe
    D:\Tools\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    F2 - REG:system.ini: UserInit=userinit.exe
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\Tools\SPYBOT~1\SDHelper.dll
    O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\System\Java\bin\jp2ssv.dll
    O3 - Toolbar: Digsby Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    O4 - HKLM\..\Run: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
    O4 - HKLM\..\Run: [PSUNMain] "D:\System\Panda Cloud Antivirus\PSUNMain.exe" /Traybar
    O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
    O4 - HKLM\..\RunOnce: [SpybotDeletingA7850] command.com /c del "C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC7493] cmd.exe /c del "C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA7825] command.com /c del "C:\Windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC2890] cmd.exe /c del "C:\Windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job"
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Tools\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9066] command.com /c del "C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD2597] cmd.exe /c del "C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5465] command.com /c del "C:\Windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD8036] cmd.exe /c del "C:\Windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job"
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOKALER DIENST')
    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOKALER DIENST')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETZWERKDIENST')
    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETZWERKDIENST')
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
    O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://D:\Doc\OFFICE~1\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\Tools\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\Tools\SPYBOT~1\SDHelper.dll
    O13 - Gopher Prefix:
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
    O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour-Dienst (Bonjour Service) - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher

    \FNPLicensingService.exe
    O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher

    \FNPLicensingService64.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
    O23 - Service: NanoServiceMain - Panda Security, S.L. - D:\System\Panda Cloud Antivirus\PSANHost.exe
    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - D:\Tools\Spybot - Search & Destroy\SDWinSec.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
    O23 - Service: Windows7FirewallService - Sphinx Software - D:\Tools\Windows7FirewallControl\Windows7FirewallService.exe
    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player

    \wmpnetwk.exe (file missing)

    --
    End of file - 8852 bytes

    I'm running Windows 7 Ultimate 64Bit
    if necessary: My other hardware ad Sysprofile

  2. #2
    Junior Member
    Join Date
    Jan 2010
    Posts
    2

    Default Edit

    Edit:

    I used a system restore point from earlier this week and it seems I'm clean!
    At least SpyBot can't find anything and the autostart-entries are gone!

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •