At around 1pm this afternoon, I clicked on the first result of a Google search and ended up being bombarded by a ton of crap.
Shortcuts popped up on my desktop, several programs were installed which I have since uninstalled from Add/Remove, and about 15 new processes came up in my Task Manager. Some came back after being terminated while new ones were still popping up. Files were copied both to my root drive and my system32 folder. Among them were:
topaff.exe
deskbar.exe
installerwnusnewer.exe
803.104.exe
deskbar_e12.exe
kybrdff_e12.exe - called Project 1
dfndrff_e12.exe
nwnmff_e12.exe
bkd.exe
wnsinttr.exe
aaa00000.dll
aaa00000.ini
aaa00000.sys
and some others that I don't recognize
AVG picked up several WINATS during the infection.
I was re-directed to a mirarsearch site when trying to uninstall the programs, and while it did uninstall the mirar toolbar, it just seemed to make things worse.
Most of this stuff was just jumbled letters and numbers with no coherency. The ones I can remember that I haven't deleted are UCmore and Batty2.exe(which still shows in processes at boot).
Most of the severe stuff I've managed to get rid of, but I still have pop-ups that appear randomly when not browsing or appear when opening a new browser window. The 2 most popular ones are Party Poker and Registry Cleaner Recommended. Others are random advertisements with videos and music and p0rn.
Here is what I've done so far:
- Trend Micro scan via Dell website
- Updated and ran Spybot, which detected a lot of stuff but had problems with 2 files that couldn't be deleted. Also had to terminate a cmd process before scanning.
- Stinger
- MRT by Microsoft
- CWShredder
- Autoruns
- smitfaudfix
- Updated and ran Ad-Aware
- CCleaner
- HijackThis 1.99. Got rid of a few things with this, but the remaining are things I'm not familiar with and therefore not sure about. Mirar is still there, as is Batty2(which won't show in processes now since I've terminated it). Those I've left alone are:
C:\WINDOWS\system32\g4400ehmeh4a0.dll (file missing)
C:\WINDOWS\SYSTEM32\igfxsrvc.dll
C:\WINDOWS\system32\dnr4019qe.dll
http://click.getmirar.com (HKLM)
http://click.mirarsearch.com (HKLM)
http://redirect.mirarsearch.com (HKLM)
http://awbeta.net-nucleus.com (HKLM)
C:\WINDOWS\system32\userinit.exe,qdrfjdq.exe
I've run a few other programs that I now can't remember, but they didn't do much anyway, or I would remember them.
Here is the whole HJ log:
Logfile of HijackThis v1.99.1
Scan saved at 10:09:51 PM, on 9/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\whatever\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:81
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,qdrfjdq.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Encarta Search Bar - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.1.0.69.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} - https://livewc02.custhelp.com/7520-b289h-turbotax/rnl/java/RntX.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8D4F501B-F723-49AF-AF71-50ED6059C3D3}: NameServer = 207.69.188.185,207.69.188.186
O20 - AppInit_DLLs: BattyRun2.dll
O20 - Winlogon Notify: AutorunsDisabled - C:\WINDOWS\
O20 - Winlogon Notify: DateTime - C:\WINDOWS\system32\g4400ehmeh4a0.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: RunOnceEx - C:\WINDOWS\system32\dnr4019qe.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\UltraVNC\winvnc.exe" -service (file missing)
Any help would be appreciated. Thanks.
Shortcuts popped up on my desktop, several programs were installed which I have since uninstalled from Add/Remove, and about 15 new processes came up in my Task Manager. Some came back after being terminated while new ones were still popping up. Files were copied both to my root drive and my system32 folder. Among them were:
topaff.exe
deskbar.exe
installerwnusnewer.exe
803.104.exe
deskbar_e12.exe
kybrdff_e12.exe - called Project 1
dfndrff_e12.exe
nwnmff_e12.exe
bkd.exe
wnsinttr.exe
aaa00000.dll
aaa00000.ini
aaa00000.sys
and some others that I don't recognize
AVG picked up several WINATS during the infection.
I was re-directed to a mirarsearch site when trying to uninstall the programs, and while it did uninstall the mirar toolbar, it just seemed to make things worse.
Most of this stuff was just jumbled letters and numbers with no coherency. The ones I can remember that I haven't deleted are UCmore and Batty2.exe(which still shows in processes at boot).
Most of the severe stuff I've managed to get rid of, but I still have pop-ups that appear randomly when not browsing or appear when opening a new browser window. The 2 most popular ones are Party Poker and Registry Cleaner Recommended. Others are random advertisements with videos and music and p0rn.
Here is what I've done so far:
- Trend Micro scan via Dell website
- Updated and ran Spybot, which detected a lot of stuff but had problems with 2 files that couldn't be deleted. Also had to terminate a cmd process before scanning.
- Stinger
- MRT by Microsoft
- CWShredder
- Autoruns
- smitfaudfix
- Updated and ran Ad-Aware
- CCleaner
- HijackThis 1.99. Got rid of a few things with this, but the remaining are things I'm not familiar with and therefore not sure about. Mirar is still there, as is Batty2(which won't show in processes now since I've terminated it). Those I've left alone are:
C:\WINDOWS\system32\g4400ehmeh4a0.dll (file missing)
C:\WINDOWS\SYSTEM32\igfxsrvc.dll
C:\WINDOWS\system32\dnr4019qe.dll
http://click.getmirar.com (HKLM)
http://click.mirarsearch.com (HKLM)
http://redirect.mirarsearch.com (HKLM)
http://awbeta.net-nucleus.com (HKLM)
C:\WINDOWS\system32\userinit.exe,qdrfjdq.exe
I've run a few other programs that I now can't remember, but they didn't do much anyway, or I would remember them.
Here is the whole HJ log:
Logfile of HijackThis v1.99.1
Scan saved at 10:09:51 PM, on 9/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\whatever\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:81
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,qdrfjdq.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Encarta Search Bar - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.1.0.69.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} - https://livewc02.custhelp.com/7520-b289h-turbotax/rnl/java/RntX.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8D4F501B-F723-49AF-AF71-50ED6059C3D3}: NameServer = 207.69.188.185,207.69.188.186
O20 - AppInit_DLLs: BattyRun2.dll
O20 - Winlogon Notify: AutorunsDisabled - C:\WINDOWS\
O20 - Winlogon Notify: DateTime - C:\WINDOWS\system32\g4400ehmeh4a0.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: RunOnceEx - C:\WINDOWS\system32\dnr4019qe.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\UltraVNC\winvnc.exe" -service (file missing)
Any help would be appreciated. Thanks.