Great forum here... love the concept of teaching people to help themselves.
My XP(sp2) pc rebooted itself for no reason 2 days ago... I ran AdaWare and Spybot Search Destroy and both found half a dozen or more items that looked dangerous. I'm not prone to picking up a lot of viruses usually and this was unusual.
I let both programs auto clean and spybot wanted to run again on bootup.
I rebooted and ran both programs again... Spybot still picked up TagASaurus but adaware showed up clear. I was busy at the time and possibly stupidly decided to work it out later... then forgot.
Today the PC rebooted for no apparent reason again (I dont have any MS or other autoupdates activated that might reboot the pc themselves, that I am aware of)
I ran both adaware and spybot again and this time there was maybe a dozen items... including one I know that I REALLY dont want to have, Win32.TrojanSpy.Goldun, which is designed to steal e-gold (which I use)
Anyway... better not make this story too long... after running those two they dont seem to be able to get rid of Win32.TrojanSpy.Goldun or TagASaurus or Coolwebsearch.
I did a bit of a search around the forum and found 2 threads where people got some help with a similar Goldun trojan before:
http://www.malwareremoval.com/forum/viewtopic.php?t=14728
and
http://www.malwareremoval.com/forum/viewtopic.php?t=14033
and tried to follow those instructions... but sadly the HaxFix utility mentioned in them doesnt pick up this version of Goldun
anyway... here is the logfile from HaxFix;
and here is the HijackThis logfile
My XP(sp2) pc rebooted itself for no reason 2 days ago... I ran AdaWare and Spybot Search Destroy and both found half a dozen or more items that looked dangerous. I'm not prone to picking up a lot of viruses usually and this was unusual.
I let both programs auto clean and spybot wanted to run again on bootup.
I rebooted and ran both programs again... Spybot still picked up TagASaurus but adaware showed up clear. I was busy at the time and possibly stupidly decided to work it out later... then forgot.
Today the PC rebooted for no apparent reason again (I dont have any MS or other autoupdates activated that might reboot the pc themselves, that I am aware of)
I ran both adaware and spybot again and this time there was maybe a dozen items... including one I know that I REALLY dont want to have, Win32.TrojanSpy.Goldun, which is designed to steal e-gold (which I use)
Anyway... better not make this story too long... after running those two they dont seem to be able to get rid of Win32.TrojanSpy.Goldun or TagASaurus or Coolwebsearch.
I did a bit of a search around the forum and found 2 threads where people got some help with a similar Goldun trojan before:
http://www.malwareremoval.com/forum/viewtopic.php?t=14728
and
http://www.malwareremoval.com/forum/viewtopic.php?t=14033
and tried to follow those instructions... but sadly the HaxFix utility mentioned in them doesnt pick up this version of Goldun
anyway... here is the logfile from HaxFix;
HAXFIX logfile - by Marckie
version 4.47
Thu 12/07/2007 14:30:18.29
--- Checking for Haxdoor ---
checking for a3d files
a3d files not found
checking for matching notify keys
no matching notify keys found
checking for matching services
matching services found
Aspi32
checking for matching safeboot services
no matching safeboot services found
checking for other Haxdoor-files
no other Haxdoor-files found
--- Checking for Goldun ---
checking for SSODL keys
no ssodl keys found
checking for notify keys
no notify keys found
checking for services
no services found
checking for other Goldun-files
no other Goldun-files found
checking iexplore.exe
iexplore.exe is not infected
--- Catchme logfile - thank you Gmer ---
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-12 14:30:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\setupact.log:cvnlxj 9728 bytes executable
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\OEWABLog.txt:tlzcmb 9728 bytes executable
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt:ongqso 11336 bytes executable
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.1:ongqso 11336 bytes executable
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.10:ongqso 11336 bytes executable
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.11:ongqso 11336 bytes executable
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.2:ongqso 11336 bytes executable
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.3:ongqso 11336 bytes executable
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.4:ongqso 11336 bytes executable
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.5:ongqso 11336 bytes executable
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.6:ongqso 11336 bytes executable
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.7:ongqso 11336 bytes executable
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.8:ongqso 11336 bytes executable
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.9:ongqso 11336 bytes executable
C:\Documents and Settings\Default\Local Settings\Temporary Internet Files\Content.IE5\QV0TMR2L\search[1].: 7324 bytes hidden from API
C:\Documents and Settings\Default\Local Settings\Temporary Internet Files\Content.IE5\S52Z4T2J\search[1].: 7001 bytes hidden from API
C:\serv.txt
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 17
--- Analysing Catchme logfile ---
no matching regkeys found
Finished!
and here is the HijackThis logfile
Logfile of HijackThis v1.99.1
Scan saved at 3:18:31 PM, on 12/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
F:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
F:\Program Files\Maxthon\Maxthon.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\SpamBayes\bin\sb_tray.exe
F:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://members.optusnet.com.au/ho.op/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = mule:8080
R3 - URLSearchHook: OI toolbar - {4319648b-98dc-4101-80c9-62f553da51de} - C:\Program Files\OI\tbOI.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: QFX Software KeyScrambler - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\keyscramblerIE.dll
O2 - BHO: OI toolbar - {4319648b-98dc-4101-80c9-62f553da51de} - C:\Program Files\OI\tbOI.dll
O2 - BHO: (no name) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - (no file)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - F:\Program Files\Roboform\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - F:\Program Files\Roboform\roboform.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: OI toolbar - {4319648b-98dc-4101-80c9-62f553da51de} - C:\Program Files\OI\tbOI.dll
O4 - HKLM\..\Run: [Mirabilis ICQ] C:\PROGRA~1\ICQ\ICQNet.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [SunServer] F:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Mail.com] C:\Program Files\mail.com\mcalert.exe -auto
O4 - HKCU\..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe
O4 - Startup: SpamBayes Tray Icon.lnk = C:\Program Files\SpamBayes\bin\sb_tray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk.disabled
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &eBay Search - res://F:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: Customize Menu - file://F:\Program Files\Roboform\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://F:\Program Files\Roboform\RoboFormComFillForms.html
O8 - Extra context menu item: IEB: Browser: Resize Window - C:\Program Files\IE Booster\window-size.html
O8 - Extra context menu item: IEB: Frame: Open in &New Window - C:\Program Files\IE Booster\frame-open-in-new-window.html
O8 - Extra context menu item: IEB: Frame: Open in &This Window - C:\Program Files\IE Booster\frame-open-in-this-window.html
O8 - Extra context menu item: IEB: Image: Copy Path to Clipboard - C:\Program Files\IE Booster\image-copy-path-to-clipboard.html
O8 - Extra context menu item: IEB: Image: Show Image Data - C:\Program Files\IE Booster\image-view-image-data.html
O8 - Extra context menu item: IEB: Image: Show Server Response - C:\Program Files\IE Booster\link-show-server-response.html
O8 - Extra context menu item: IEB: Link: Copy as <A href="URL">caption</A> - C:\Program Files\IE Booster\link-copy.html
O8 - Extra context menu item: IEB: Link: Open in New Minimized Window - C:\Program Files\IE Booster\link-open-minimized.html
O8 - Extra context menu item: IEB: Link: Show Server Response - C:\Program Files\IE Booster\link-show-server-response.html
O8 - Extra context menu item: IEB: Page: Copy Title as <A href="URL">Title</a> - C:\Program Files\IE Booster\page-copy-title.html
O8 - Extra context menu item: IEB: Page: Show Forms and Applets - C:\Program Files\IE Booster\page-show-forms.html
O8 - Extra context menu item: IEB: Page: Show Hyperlinks - C:\Program Files\IE Booster\page-view-hyperlinks.html
O8 - Extra context menu item: IEB: Page: Show Images - C:\Program Files\IE Booster\page-show-images.html
O8 - Extra context menu item: IEB: Page: Show Source - C:\Program Files\IE Booster\page-view-source.html
O8 - Extra context menu item: IEB: Page: Show Stylesheets - C:\Program Files\IE Booster\page-view-stylesheets.html
O8 - Extra context menu item: IEB: Page: Show TABLE, FORM and DIV Borders - C:\Program Files\IE Booster\page-show-table-structure.htm
O8 - Extra context menu item: IEB: Selection: Copy as plain text - C:\Program Files\IE Booster\selection-copy-plaintext.html
O8 - Extra context menu item: IEB: Selection: Open in Browser - C:\Program Files\IE Booster\selection-open-in-browser.html
O8 - Extra context menu item: IEB: Selection: Show Partial Source - C:\Program Files\IE Booster\selection-show-source.html
O8 - Extra context menu item: MT It! - http://www.abuseblog.com/cgi-bin/mt.cgi?__mode=reg_bm_js&bm_show=trackback,category&bm_height=540
O8 - Extra context menu item: RoboForm Toolbar - file://F:\Program Files\Roboform\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://F:\Program Files\Roboform\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://F:\Program Files\Roboform\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://F:\Program Files\Roboform\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://F:\Program Files\Roboform\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://F:\Program Files\Roboform\RoboFormComSavePass.html
O9 - Extra button: (no name) - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\keyscramblerIE.dll
O9 - Extra 'Tools' menuitem: &KeyScrambler... - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\keyscramblerIE.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://F:\Program Files\Roboform\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://F:\Program Files\Roboform\RoboFormComShowToolbar.html
O9 - Extra button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra 'Tools' menuitem: Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - F:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - F:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: http://www.indirectlinking.com
O15 - Trusted Zone: *.indirectlinking.com
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O16 - DPF: ChatSpace Full Java Client 4.0.0.320 - http://irc.everywherechat.com/Java/cfs40320.cab
O16 - DPF: ConferenceRoom Java Client - http://chat.privatefeeds.com:8000/java/cr.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {4B48D5DF-9021-45F7-A240-60304302A215} -
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} -
O16 - DPF: {72D59B9C-1E59-4958-803A-ABDEE2D4CFA6} (DivX Player) - http://download.divx.com/player/DivXPlayerInstaller.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} (IntraLaunch.MainControl) -
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/a ... _en_dl.cab
O16 - DPF: {B9A296D4-38AC-4566-8168-F7ACAF7D35E6} -
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/popcap/zuma/popcaploader_v6.cab
O16 - DPF: {EA1B8527-E422-4909-825A-70BE0694F18E} (PortfolioManagerWT ProfileManager Class) - https://online.bank.com.au/wtpbs/wtBala ... agerwt.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} -
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: UQLBGFKXT - Unknown owner - C:\DOCUME~1\Default\LOCALS~1\Temp\UQLBGFKXT.exe (file missing)