View Single Post
  #3 (permalink)  
Old 14-05-2009, 01:13 AM
dn_kredible dn_kredible is offline
Junior Member
New Recruit
 
Join Date: May 2009
Posts: 38
dn_kredible deserves a pat on the back from everyonedn_kredible deserves a pat on the back from everyonedn_kredible deserves a pat on the back from everyonedn_kredible deserves a pat on the back from everyonedn_kredible deserves a pat on the back from everyonedn_kredible deserves a pat on the back from everyonedn_kredible deserves a pat on the back from everyone
Re: I have a Win32/Hidrag virus and looking for help

SUPERAntiSpyware Free Edition did not find any infections

GWER always makes me log out, I don't know if its bugged or something.

Malwarebytes' Anti-Malware log

Malwarebytes' Anti-Malware 1.36
Database version: 2127
Windows 5.1.2600 Service Pack 3

5/13/2009 7:46:48 PM
mbam-log-2009-05-13 (19-46-37).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 226340
Time elapsed: 2 hour(s), 37 minute(s), 28 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 5
Files Infected: 7

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\ErrorSmart (Rogue.ErrorSmart) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\ErrorSmart (Rogue.ErrorSmart) -> No action taken.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Documents and Settings\Dad\Application Data\ErrorSmart (Rogue.ErrorSmart) -> No action taken.
C:\Documents and Settings\Dad\Application Data\ErrorSmart\Log (Rogue.ErrorSmart) -> No action taken.
C:\Documents and Settings\Dad\Application Data\ErrorSmart\Registry Backups (Rogue.ErrorSmart) -> No action taken.
C:\Documents and Settings\Owner\Application Data\ErrorSmart (Rogue.ErrorSmart) -> No action taken.
C:\Documents and Settings\Owner\Application Data\ErrorSmart\Log (Rogue.ErrorSmart) -> No action taken.

Files Infected:
C:\Documents and Settings\Dad\Application Data\ErrorSmart\Log\2008 Aug 30 - 08_51_46 PM_375.log (Rogue.ErrorSmart) -> No action taken.
C:\Documents and Settings\Dad\Application Data\ErrorSmart\Registry Backups\2008-08-24_02-51-48.reg (Rogue.ErrorSmart) -> No action taken.
C:\Documents and Settings\Dad\Application Data\ErrorSmart\Registry Backups\2008-08-24_03-15-28.reg (Rogue.ErrorSmart) -> No action taken.
C:\Documents and Settings\Dad\Application Data\ErrorSmart\Registry Backups\2008-08-27_18-51-18.reg (Rogue.ErrorSmart) -> No action taken.
C:\Documents and Settings\Dad\Application Data\ErrorSmart\Registry Backups\2008-08-27_18-51-50.reg (Rogue.ErrorSmart) -> No action taken.
C:\Documents and Settings\Owner\Application Data\ErrorSmart\Log\2008 Aug 29 - 06_35_42 PM_750.log (Rogue.ErrorSmart) -> No action taken.
C:\Documents and Settings\Owner\Application Data\ErrorSmart\Log\2008 Aug 29 - 08_50_09 PM_593.log (Rogue.ErrorSmart) -> No action taken.

I have error smart pro for awhile now, I really don't think its infecting my PC.


HiJack This log


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:06:41 PM, on 5/13/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Dad\Desktop\Programs\PC Tools\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Yahoo!
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Yahoo!
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = 0.0.0.0:80
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User '?')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User '?')
O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\System32\shdocvw.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

--
End of file - 3268 bytes



This is a report from my AVG 08' residental shield findings as of May 13th

Resident Shield detection
"Infection";"Object";"Result";"Detection time";"Object Type";"Process"
"Virus identified Win32/Hidrag.A";"C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP33\A0007406.exe";"Moved to Virus Vault";"5/13/2009, 2:57:02 PM";"file";"C:\WINDOWS\system32\svchost.exe"
"Virus identified Win32/Hidrag.A";"C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP33\A0007406.exe";"Infected";"5/12/2009, 10:15:36 PM";"file";"C:\WINDOWS\system32\svchost.exe"
"Virus identified Win32/Hidrag.A";"C:\Documents and Settings\Dad\My Documents\Downloads\Counter-Strike Source FULL [October 15 2007] DiGiTALZonE\CSS_FULL_Oct-15-07_DiGiTALZonE_2FINISH.exe";"Deleted";"5/12/2009, 6:02:49 PM";"file";"C:\Documents and Settings\Dad\Desktop\Programs\Apps\uTorrent.exe"
Reply With Quote