This thread's last reply is from February 16, 2010, 5:08 AM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
Brood
Hi
The Java section was followed to the letter.
VirusTotal Results below:
MD5: f80f6e09e7f4bafe478ca0da6137e1e2
First received: 2009.12.15 10:56:33 UTC
Date: 2010.02.12 16:11:30 UTC [<1D]
Results: 3/40
Permalink: analisis/682fd0d13d7caf4b17a1eb9bafa0a3c3598139bb3623d3f5fba3bfbd0a6d424a-1265991090
=========================================================================================================
OTL Results:
All processes killed
========== OTL ==========
Service epmntdrv stopped successfully!
Service epmntdrv deleted successfully!
E:\WINDOWS\system32\epmntdrv.sys moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\esentclbClient deleted successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\E:\Program Files\Steam\Steam.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\E:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\E:\Program Files\Steam\steamapps\liquidsun\team fortress 2\hl2.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\E:\Program Files\Steam\steamapps\common\arma 2\arma2.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\D:\Program Files\Dragon Age Origins Character Creator\bin_ship\DAOCharacterCreator.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\D:\Program Files\Dragon Age Origins Character Creator\DAOriginsLauncher.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\E:\Program Files\Steam\steamapps\common\empire total war\Empire.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\E:\Program Files\Steam\steamapps\common\left 4 dead\left4dead.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\E:\Program Files\Steam\steamapps\common\overlord\Overlord.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\E:\Program Files\Steam\steamapps\common\overlord\Config.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\E:\Program Files\Steam\steamapps\common\overlord ii\Overlord2.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\E:\Program Files\Steam\steamapps\common\overlord ii\Config.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\E:\Program Files\Steam\steamapps\common\plants vs zombies\PlantsVsZombies.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\E:\Program Files\Steam\steamapps\common\osmos\osmos.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\E:\Program Files\Steam\steamapps\common\trine\trine_launcher.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\E:\Program Files\Steam\steamapps\common\swkotor\swkotor.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\E:\Program Files\Steam\steamapps\common\evil genius\EvilGeniusLauncher.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\E:\Program Files\Steam\steamapps\common\dawn of war gold\W40kWA.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\E:\Program Files\Steam\steamapps\common\dawn of war gold\W40k.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\E:\Program Files\Steam\steamapps\common\company of heroes\help.htm deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\E:\Program Files\Steam\steamapps\common\company of heroes\RelicCOH.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\G:\D\GAMES DIR\CALLOFJUAREZ\COJBIBGAME_X86.EXE deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\E:\Program Files\Steam\steamapps\common\mirrors edge\Binaries\MirrorsEdge.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\E:\Program Files\Steam\steamapps\common\dawn of war dark crusade\darkcrusade.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\E:\Program Files\Steam\steamapps\common\dawn of war soulstorm\soulstorm.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\E:\Program Files\Steam\steamapps\common\stalker shadow of chernobyl\bin\XR_3DA.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\E:\Program Files\Steam\steamapps\common\left 4 dead 2\left4dead2.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Steam\steamapps\common\empire total war\Empire.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Steam\steamapps\common\shattered_horizon\client_exe\shattered_horizon.exe deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: All Users
User: Barry
->Temp folder emptied: 189941456 bytes
->Temporary Internet Files folder emptied: 919461328 bytes
->Java cache emptied: 51070959 bytes
->FireFox cache emptied: 49760238 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2162283 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 82772 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 12981022 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 4729297659 bytes
Total Files Cleaned = 5,679.00 mb
OTL by OldTimer - Version 3.1.28.0 log created on 02122010_194540
Files\Folders moved on Reboot...
E:\Documents and Settings\Barry\Local Settings\Temp\WCESLog.log moved successfully.
Registry entries deleted on Reboot...
Vino Rosso
Hi
Thanks for posting the logs.
I'm trying to discover what the mvjvsng3.exe file is. Do you recognise it?
Can you please upload the file here: http://www.bleepingcomputer.com/submit-malware.php?channel=36
And, if you don't recognise it, please delete it.
How is the computer now running?
Brood
Hi Vino
I still get the odd redirection, usually to google but sometimes to other ad sites.
Yes it's GMER from this post:
Gmer
Download GMER Rootkit Scanner from here.
Please physically disconnect from the internet and disable the computer's security programs as these may interfere with GMER.
* Double click the .exe file. If asked to allow gmer.sys driver to load, please consent
* If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO << Important!
Image
Click the image to enlarge it
* In the right panel, you will see several boxes that have been checked. UNcheck the following ...
o UNcheck Sections
o UNcheck IAT/EAT
o UNcheck Drives/Partition other than Systemdrive (typically C:\)
o UNcheck Show All (don't miss this one)
* Then click the Scan button & wait for it to finish
* Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file
* Save it where you can easily find it, such as your desktop, and post it in reply
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries
Note: Do not run any programs while Gmer is running.
Re-enable the computer's security programs and connect to the internet.
To post in next reply:
Contents of DDS log
Contents of Attach.txt
Contents of Gmer log
Vino Rosso
Funny that... I suspected GMER but looked at my copy and saw a larger file size. Now, of course, I realise I haven't run it so was looking at the installation file.
Can you please remind me, do you get these occasional re-directs with more than one browser?
Brood
I only use firefox really, the odd time I use IE (testing website layouts) I never get a problem. Recently I've been using IE a few times a day. With firefox I will only get redirected once or twice a day bearing in mind I browse a lot during any given day.
Brood
GooredFix by jpshortstuff (08.01.10.1)
Log created at 11:54 on 13/02/2010 (Barry)
Firefox version 3.5.7 (en-GB)
========== GooredScan ==========
========== GooredLog ==========
E:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd} [07:22 08/10/2009]
{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} [10:13 13/10/2009]
{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} [18:43 12/02/2010]
E:\Documents and Settings\Barry\Application Data\Mozilla\Firefox\Profiles\hwpdatzi.default\extensions\
en-GB @ dictionaries.addons.mozilla.org [11:59 16/12/2009]
firebug @ software.joehewitt.com [11:18 09/02/2010]
LogMeInClient @ logmein.com [13:08 21/11/2009]
{20a82645-c095-46ed-80e3-08825760534b} [08:26 08/10/2009]
{3d7eb24f-2740-49df-8937-200b1cc08f8a} [14:06 30/01/2010]
{73a6fe31-595d-460b-a920-fcc0f8843232} [16:58 05/02/2010]
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{20a82645-c095-46ed-80e3-08825760534b}"="E:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [20:09 27/09/2009]
"{3f963a5b-e555-4543-90e2-c3908898db71}"="E:\Program Files\AVG\AVG9\Firefox" [07:36 05/01/2010]
"[removed]"="E:\Program Files\Java\jre6\lib\deploy\jqs\ff" [18:43 12/02/2010]
-=E.O.F=-
NonSuch
As this issue appears to be resolved,