Malware XxX.xXx and UuU.uUu

Solved
aleg17 Posted messages 30 Registration date   Status Member Last intervention   -  
Smart91 Posted messages 30146 Status Security Contributor -
Hello,
For a few days now, Malwarebytes found this:

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 8035

Windows 6.1.7600
Internet Explorer 9.0.7930.16406

10/28/2011 7:13:40 PM
mbam-log-2011-10-28 (19-13-37).txt

Scan type: Quick scan
Item(s) scanned: 123365
Elapsed time: 1 minute(s), 3 second(s)

Infected memory processes: 0
Infected memory modules: 0
Infected Registry keys: 0
Infected Registry values: 0
Infected Registry data items: 0
Infected folders: 0
Infected files: 6

Infected memory processes:
(No harmful items detected)

Infected memory modules:
(No harmful items detected)

Infected Registry keys:
(No harmful items detected)

Infected Registry values:
(No harmful items detected)

Infected Registry data items:
(No harmful items detected)

Infected folders:
(No harmful items detected)

Infected files:
c:\Users\Alex\AppData\Roaming\logs.dat (Bifrose.Trace) -> No action taken.
c:\Users\Alex\AppData\Local\Temp\IELOGIN.abc (Malware.Trace) -> No action taken.
c:\Users\Alex\AppData\Local\Temp\MSN.abc (Malware.Trace) -> No action taken.
c:\Users\Alex\AppData\Local\Temp\UuU.uUu (Malware.Trace) -> No action taken.
c:\Users\Alex\AppData\Local\Temp\XxX.xXx (Malware.Trace) -> No action taken.
c:\Users\Alex\AppData\Local\Temp\xxxyyyzzz.dat (Malware.Trace) -> No action taken.

and I can’t seem to delete them (I’m not an EXPERT)
if someone could help me
THANK YOU

Configuration: Windows 7 / Safari 535.1

48 answers

  • 1
  • 2
  • 3
  1. Smart91 Posted messages 30146 Status Security Contributor 2 331
     
    Hello,

    * Restart MBAM and let the Updates download (otherwise do it manually when launching the program). It's very important
    * Then go to the "Scan" tab, check "Run a full scan" and then click "Scan"
    * Don't worry, the scan may take several hours depending on the number of files and infections to analyze
    * At the end of the scan, click on "Show results"
    * Check all detected items and then click on "Delete selected"
    * Save the report
    * If prompted to restart the computer, click Yes
    * A report will appear after deletion: post it in your next reply.

    Smart
    --
    ""If you have no ambitions, you settle down at the edge of the fall" (Kundera)
    1
  2. aleg17 Posted messages 30 Registration date   Status Member Last intervention  
     
    ok here is the report:

    Malwarebytes' Anti-Malware 1.51.2.1300
    www.malwarebytes.org

    Database version: 8036

    Windows 6.1.7600
    Internet Explorer 9.0.7930.16406

    10/28/2011 21:11:44
    mbam-log-2011-10-28 (21-11-38).txt

    Scan type: Full scan (C:\|D:\|E:\|G:\|)
    Item(s) scanned: 336174
    Time elapsed: 1 hour(s), 5 minute(s), 29 second(s)

    Infected memory process(es): 0
    Infected memory module(s): 0
    Infected Registry key(s): 0
    Infected Registry value(s): 0
    Infected Registry data item(s): 0
    Infected folder(s): 0
    Infected file(s): 6

    Infected memory process(es):
    (No harmful items detected)

    Infected memory module(s):
    (No harmful items detected)

    Infected Registry key(s):
    (No harmful items detected)

    Infected Registry value(s):
    (No harmful items detected)

    Infected Registry data item(s):
    (No harmful items detected)

    Infected folder(s):
    (No harmful items detected)

    Infected file(s):
    c:\Users\Alex\AppData\Roaming\logs.dat (Bifrose.Trace) -> No action taken.
    c:\Users\Alex\AppData\Local\Temp\IELOGIN.abc (Malware.Trace) -> No action taken.
    c:\Users\Alex\AppData\Local\Temp\MSN.abc (Malware.Trace) -> No action taken.
    c:\Users\Alex\AppData\Local\Temp\UuU.uUu (Malware.Trace) -> No action taken.
    c:\Users\Alex\AppData\Local\Temp\XxX.xXx (Malware.Trace) -> No action taken.
    c:\Users\Alex\AppData\Local\Temp\xxxyyyzzz.dat (Malware.Trace) -> No action taken.
    aleg17
    0
  3. Smart91 Posted messages 30146 Status Security Contributor 2 331
     
    You didn't follow what I said, which is to
    check all detected items and then click on "Delete selection" after the scan
    or you didn't post the correct report.
    If that's the case, you're going to do this:
    - Relaunch MBAM
    - Go to the "Report/Logs" tab
    - Double-click on the latest report by date
    - Copy this report and post it in your response

    Smart
    --
    "If you have no ambitions, you settle at the edge of the abyss" (Kundera)
    0
  4. aleg17 Posted messages 30 Registration date   Status Member Last intervention  
     
    Sorry ... here it is, normally it's the right one

    Malwarebytes' Anti-Malware 1.51.2.1300
    www.malwarebytes.org

    Database version: 8036

    Windows 6.1.7600
    Internet Explorer 9.0.7930.16406

    28/10/2011 21:12:01
    mbam-log-2011-10-28 (21-12-01).txt

    Scan type: Full scan (C:\|D:\|E:\|G:\|)
    Item(s) scanned: 336174
    Elapsed time: 1 hour(s), 5 minute(s), 29 second(s)

    Infected memory process(es): 0
    Infected memory module(s): 0
    Infected registry key(s): 0
    Infected registry value(s): 0
    Infected registry data item(s): 0
    Infected folder(s): 0
    Infected file(s): 6

    Infected memory process(es):
    (No threats detected)

    Infected memory module(s):
    (No threats detected)

    Infected registry key(s):
    (No threats detected)

    Infected registry value(s):
    (No threats detected)

    Infected registry data item(s):
    (No threats detected)

    Infected folder(s):
    (No threats detected)

    Infected file(s):
    c:\Users\Alex\AppData\Roaming\logs.dat (Bifrose.Trace) -> Quarantined and deleted successfully.
    c:\Users\Alex\AppData\Local\Temp\IELOGIN.abc (Malware.Trace) -> Quarantined and deleted successfully.
    c:\Users\Alex\AppData\Local\Temp\MSN.abc (Malware.Trace) -> Quarantined and deleted successfully.
    c:\Users\Alex\AppData\Local\Temp\UuU.uUu (Malware.Trace) -> Quarantined and deleted successfully.
    c:\Users\Alex\AppData\Local\Temp\XxX.xXx (Malware.Trace) -> Quarantined and deleted successfully.
    c:\Users\Alex\AppData\Local\Temp\xxxyyyzzz.dat (Malware.Trace) -> Quarantined and deleted successfully.
    aleg17
    0
  5. aleg17 Posted messages 30 Registration date   Status Member Last intervention  
     
    I'm going to bed A +

    Aleg17
    0
  6. Smart91 Posted messages 30146 Status Security Contributor 2 331
     
    This time it's good.

    Restart MBAM and clear the quarantine.

    We're still going to perform a diagnostic on your PC to see if there are any other infections.

    Download ZHPDiag (by Nicolas Coolman) to your desktop
    https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html
    or from this link if the first one has issues:
    http://www.moncompteur.com/compteurclick.php?idLink=18026

    Once the download is finished, double click on ZHPDiag.exe and follow the instructions.

    /!\Vista and Windows 7 users: Right-click on the ZHPDiag.exe logo, "run as Administrator"

    Don't forget to check the box that allows you to create a shortcut on the desktop.
    - Double click on the ZHPDiag shortcut on your desktop to launch it.
    - If you have Avast 6 as antivirus, at the alert choose "run normally"
    (/!\The tool has created 2 icons ZHPDiag and ZHPFix)
    - Click on the magnifying glass to start the scan.
    - Let the tool work, it may take some time.
    - Close ZHPDiag at the end of the scan.
    - To send the report click on this link: http://www.cijoint.fr/
    - Click on Browse and find the directory where ZHPDiag is installed (usually C:\ZHP\).
    - Select the ZHPDiag.txt file.
    - Click on "Click here to upload the file".
    - A link like this: http://www.cijoint.fr/cjlink.php?file=cj200905/cijSKAP5fU.txt will be added to the page.
    - Copy this link into your reply.

    Smart
    "If you have no ambitions, you settle at the edge of the fall" (Kundera)
    0
  7. aleg17 Posted messages 30 Registration date   Status Member Last intervention  
     
    Hello Smart

    here is the link:
    http://www.cijoint.fr/cjlink.php?file=cj201110/cijgp6T2j7.txt

    aleg17
    0
  8. Smart91 Posted messages 30146 Status Security Contributor 2 331
     
    Uninstall Spybot Search & Destroy, it is useless today and only slows down your PC ==>
    https://www.commentcamarche.net/faq/7371-desinstaller-proprement-spybot-search-and-destroy-1-6

    Malekal's article on the uselessness of Spybot, SuperAntispyware, and Adaware:
    https://www.malekal.com/superantispyware-et-spybot-vs-malwarebyte/

    There are still traces. We will use specific software and if they are still there, we will remove them manually.

    - Download AdwCleaner from Xplode to your desktop
    - Choose "Delete" and post the report

    Smart
    --
    "If you have no ambitions, you settle for the edge of the fall" (Kundera)
    0
  9. aleg17 Posted messages 30 Registration date   Status Member Last intervention  
     
    I uninstalled Spybot
    however, the AdwCleaner site is under maintenance.
    Another question, it asks for a username and a password.???
    aleg17
    0
  10. Smart91 Posted messages 30146 Status Security Contributor 2 331
     
    You're right, I had forgotten.

    Go to the backup site here ==>
    http://www.alc-badminton.fr/downloads/general-changelog/Xplode/

    And download Adwcleaner, it's the first one on the list.

    Smart
    --
    "If you have no ambitions, you settle on the edge of the fall" (Kundera)
    0
  11. aleg17 Posted messages 30 Registration date   Status Member Last intervention  
     
    I can't post the report?????

    Is it too large???

    aleg17
    0
  12. aleg17 Posted messages 30 Registration date   Status Member Last intervention  
     
    I think it's good, here is the link:

    http://www.cijoint.fr/cjlink.php?file=cj201110/cijIz4RWMc.txt

    aleg17
    0
  13. Smart91 Posted messages 30146 Status Security Contributor 2 331
     
    Use this site to submit the report and give me the link to access it

    http://cijoint.fr

    Smart
    --
    "If you have no ambitions, you settle down at the edge of the abyss" (Kundera)
    0
  14. aleg17 Posted messages 30 Registration date   Status Member Last intervention  
     
    Yes, it's done, sorry for the inconvenience.

    aleg17
    0
  15. Smart91 Posted messages 30146 Status Security Contributor 2 331
     
    OK redo a ZHPDiag scan and post the report via cijoint

    Smart
    --
    "If you have no ambitions, you settle on the edge of the fall" (Kundera)
    0
  16. aleg17 Posted messages 30 Registration date   Status Member Last intervention  
     
    Here is the link

    http://www.cijoint.fr/cjlink.php?file=cj201110/cijF5iHJzk.txt

    aleg17
    0
  17. Smart91 Posted messages 30146 Status Security Contributor 2 331
     
    There are traces left

    - Close all your running applications
    - Launch ZHPFix (either via the shortcut on your Desktop or via ZHPDiag by clicking on the green shield)
    If you don't have it, download it from this link: https://www.zebulon.fr/telechargements/securite/systeme/zhpfix.html
    Copy/paste the following bold lines:

    ----------------------------------------------------------
    [HKCU\Software\Moovida]
    [HKCU\Software\Spointer]
    [HKCU\Software\ilivid]
    [HKLM\Software\CrazyLoader]
    O43 - CFD: 21/03/2011 - 20:14:48 - [11525560] ----D- C:\Users\Alex\AppData\Roaming\moovida-1
    O43 - CFD: 21/03/2011 - 20:14:50 - [401268] ----D- C:\Users\Alex\AppData\Local\moovida Air
    [HKLM\Software\Classes\Toolbar.CT2542115]
    [HKLM\Software\Classes\Toolbar.CT2613520]
    [HKLM\Software\Classes\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5}]
    [HKLM\Software\CrazyLoader]
    [HKCU\Software\ilivid]
    [HKCU\Software\Spointer]
    C:\Users\Alex\AppData\Local\moovida air
    C:\Users\Alex\AppData\LocalLow\Toolbar4
    R3 - URLSearchHook: (no name) - {4daac69c-cba7-45e2-9bc8-1044483d3352} . (...) (No version) -- (.not file.)
    [HKCU\Software\ASK Homework]
    [HKCU\Software\AppDataLow\Software\toolbar]
    [HKCU\Software\AppDataLow\Software\Toolbar]
    [MD5.00000000000000000000000000000000] [APT] [Ad-Aware Update (Weekly)] (...) -- C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe (.not file.)
    [MD5.00000000000000000000000000000000] [APT] [{03C96023-0C3E-4836-980F-AAE3B1739C5F}] (...) -- C:\Program Files\Xilisoft\DVD Ripper Standard 5\Uninstall.exe (.not file.)
    EmptyTemp
    EmptyFlash
    FirewallRAZ

    ----------------------------------------------------------
    - Click on the icon representing the letter H (“paste Helper lines”)
    - The lines will automatically paste into ZHPFix, if not paste the lines
    - Click on the “GO” button to start the cleanup
    - Copy/paste the entire report in your next reply

    Smart
    --
    "If you have no ambitions, you settle on the edge of the fall” (Kundera)
    0
  18. aleg17 Posted messages 30 Registration date   Status Member Last intervention  
     
    ZHPFix Report 1.12.3366 by Nicolas Coolman, Update of 26/10/2011
    Export Registry File:
    Run by Alex at 29/10/2011 16:53:51
    Windows 7 Ultimate Edition, 32-bit (Build 7600)
    Web site: http://www.premiumorange.com/zeb-help-process/zhpfix.html

    ========== Registry Key(s) ==========
    DELETE Key: HKCU\Software\Moovida
    DELETE Key: HKCU\Software\Spointer
    DELETE Key: HKCU\Software\ilivid
    DELETE Key: HKLM\Software\CrazyLoader
    DELETE Key: HKLM\Software\Classes\Toolbar.CT2542115
    DELETE Key: HKLM\Software\Classes\Toolbar.CT2613520
    DELETE Key: HKLM\Software\Classes\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5}
    DELETE Key: HKCU\Software\ASK Homework
    DELETE Key: HKCU\Software\AppDataLow\Software\toolbar
    ABSENT Key: HKCU\Software\AppDataLow\Software\Toolbar

    ========== Registry Value(s) ==========
    DELETE URLSearchHook: {4daac69c-cba7-45e2-9bc8-1044483d3352}
    ABSENT Value Domain Profile: FirewallRaz:
    DELETE FirewallRaz (Public): {33544D34-65D3-4C89-AEB8-8A7FD09DCD08}
    DELETE FirewallRaz (Public): {5E95EF1E-B62B-4401-B67D-7E3129B7DE88}
    DELETE FirewallRaz (Private): {F07FD032-52C3-4125-8C7C-D0CFF9C0E020}
    DELETE FirewallRaz (Private): {9130008E-5CDA-4ADB-9980-C3AACA4D28F3}
    DELETE FirewallRaz (Private): {5FD531F3-7B1C-47C4-A342-C243D59787CF}
    DELETE FirewallRaz (Private): {8252BBA0-B3A3-45ED-B447-31109300CE08}
    DELETE FirewallRaz (Private): {CB0C3A6D-ED86-4FD5-85E8-0893E70A2524}
    DELETE FirewallRaz (Private): {95F04895-E2C8-477E-AFF9-160F1524F756}
    DELETE FirewallRaz (Private): {7179F542-1F2F-4099-9AB3-078CC9A170E7}
    DELETE FirewallRaz (Private): {9F7F13D8-98AE-4A27-BE62-8D7B4ECD51C7}

    ========== Folder(s) ==========
    DELETE Folder: C:\Users\Alex\AppData\Roaming\moovida-1
    DELETE Folder: C:\Users\Alex\AppData\Local\moovida Air
    DELETE Folder: c:\users\alex\appdata\locallow\toolbar4
    DELETE Windows Temporary: 72
    DELETE Flash Cookies: 13

    ========== File(s) ==========
    ABSENT Folder/File: c:\users\alex\appdata\local\moovida air
    DELETE Windows Temporary: 53
    DELETE Flash Cookies: 5

    ========== Scheduled Task ==========
    DELETE Task: Ad-Aware Update (Weekly)
    DELETE Task: {03C96023-0C3E-4836-980F-AAE3B1739C5}

    ========== Summary ==========
    10: Registry Key(s)
    12: Registry Value(s)
    5: Folder(s)
    3: File(s)
    2: Scheduled Task

    End of clean in 00mn 05s

    ========== Report file path ==========
    C:\ZHP\ZHPFix[R1].txt - 29/10/2011 16:53:51 [2487]
    aleg17
    0
  19. Smart91 Posted messages 30146 Status Security Contributor 2 331
     
    Great

    Re-run ZHPDiag click on the green arrow to install the update, run a scan again and post the report via attachment.
    Then we will move on to the final phase. Here’s what we have left to do:
    - the priority updates
    - the PC optimization
    - the uninstallation of the cleanup tools
    - prevention tips when surfing the Internet

    Smart
    --
    "If you have no ambitions, you're settling for the edge of the abyss" (Kundera)
    0
  20. aleg17 Posted messages 30 Registration date   Status Member Last intervention  
     
    I'm sorry, but I cannot access external links.
    0
  • 1
  • 2
  • 3