mebaby333
asked on
Virus creates an icon with a computer and replicates "My Computer"
Does anyone have any info on a virus that creates an additional computer icon. When you click the plus it basically shows the contents of "my computer" and it continues forever? The icon's properties says it is approx 15mb yet it is continuous.. it also has no indication of being simply a shortcut.
I have scanned this computer and it is scanning clean after I used; adwcleaner, malwarebytes, malwarebytes rootkit scanner, and rogue killer.
I am still noticing that since this began the user has not been able to attach pictures from his my doc folder. I went in and reset his permissions and tried to stop his antivirus and send and it did not correct the issue. I had another post some time back where the Outlook issue occurred with another user
The system is an Windows XP sp3 and I am including the adwcleaner log and will attach a screen shot of the replicating my computer deal the name of it is "32788R22FWJFW"...
# AdwCleaner v3.015 - Report created 17/12/2013 at 10:13:41
# Updated 10/12/2013 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : jfischer - QTYMANAGER
# Running from : E:\adwcleaner.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Found C:\Documents and Settings\Administrator.SIL VER\Local Settings\Application Data\AskToolbar
Folder Found C:\Documents and Settings\jfischer\Applicat ion Data\alotappbar
Folder Found C:\Documents and Settings\jfischer\Local Settings\Application Data\AskToolbar
Folder Found C:\Documents and Settings\jfischer\Local Settings\Application Data\PackageAware
Folder Found C:\Program Files\alotappbar
Folder Found C:\Program Files\Ask.com
Folder Found C:\WINDOWS\installer\{86d4 b82a-abed- 442a-be86- 96357b70f4 fe}
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\alotAppbar
Key Found : HKCU\Software\AppDataLow\A skToolbarI nfo
Key Found : HKCU\Software\Ask.com
Key Found : HKCU\Software\AskToolbar
Key Found : HKCU\Software\Microsoft\In ternet Explorer\SearchScopes\{171 DEBEB-C3D4 -40B7-AC73 -056A5EBA4 A7E}
Key Found : HKCU\Software\Microsoft\In ternet Explorer\SearchScopes\{A53 1D99C-5A22 -449B-83DA -872725C6D 0ED}
Key Found : HKCU\Software\Microsoft\Wi ndows\Curr entVersion \Ext\Setti ngs\{02478 D38-C3F9-4 EFB-9B51-7 695ECA0567 0}
Key Found : HKCU\Software\Microsoft\Wi ndows\Curr entVersion \Ext\Setti ngs\{16315 50F-191D-4 826-B069-D 9439253D92 6}
Key Found : HKCU\Software\Microsoft\Wi ndows\Curr entVersion \Ext\Setti ngs\{85F5C F95-EC8F-4 9FC-BB3F-3 8C79455CBA 2}
Key Found : HKCU\Software\Microsoft\Wi ndows\Curr entVersion \Ext\Setti ngs\{A531D 99C-5A22-4 49B-83DA-8 72725C6D0E D}
Key Found : HKCU\Software\Microsoft\Wi ndows\Curr entVersion \Ext\Setti ngs\{D4027 C7F-154A-4 066-A1AD-4 243D812744 0}
Key Found : HKCU\Software\Microsoft\Wi ndows\Curr entVersion \Ext\Setti ngs\{EF99B D32-C1FB-1 1D2-892F-0 090271D4F8 8}
Key Found : HKCU\Software\Microsoft\Wi ndows\Curr entVersion \Ext\Stats \{02478D38 -C3F9-4EFB -9B51-7695 ECA05670}
Key Found : HKCU\Software\Microsoft\Wi ndows\Curr entVersion \Ext\Stats \{1631550F -191D-4826 -B069-D943 9253D926}
Key Found : HKCU\Software\Microsoft\Wi ndows\Curr entVersion \Ext\Stats \{85F5CF95 -EC8F-49FC -BB3F-38C7 9455CBA2}
Key Found : HKCU\Software\Microsoft\Wi ndows\Curr entVersion \Ext\Stats \{A531D99C -5A22-449B -83DA-8727 25C6D0ED}
Key Found : HKCU\Software\Microsoft\Wi ndows\Curr entVersion \Ext\Stats \{D4027C7F -154A-4066 -A1AD-4243 D8127440}
Key Found : HKCU\Software\Microsoft\Wi ndows\Curr entVersion \Ext\Stats \{EF99BD32 -C1FB-11D2 -892F-0090 271D4F88}
Key Found : HKCU\Software\YahooPartner Toolbar
Key Found : HKLM\SOFTWARE\Classes\AppI D\{4D076AB 4-7562-427 A-B5D2-BD9 6E19DEE56}
Key Found : HKLM\SOFTWARE\Classes\AppI D\{9B0CB95 C-933A-4B8 C-B6D4-EDC D19A43874}
Key Found : HKLM\SOFTWARE\Classes\AppI D\GenericA skToolbar. DLL
Key Found : HKLM\SOFTWARE\Classes\AppI D\secman.D LL
Key Found : HKLM\SOFTWARE\Classes\CLSI D\{0000000 0-6E41-4FD 3-8538-502 F5495E5FC}
Key Found : HKLM\SOFTWARE\Classes\CLSI D\{02478D3 8-C3F9-4EF B-9B51-769 5ECA05670}
Key Found : HKLM\SOFTWARE\Classes\CLSI D\{20E1481 B-E285-4AB C-ADC7-AE2 4842B81CD}
Key Found : HKLM\SOFTWARE\Classes\CLSI D\{66EEF54 3-A9AC-4A9 D-AA3C-1ED 148AC8EEE}
Key Found : HKLM\SOFTWARE\Classes\CLSI D\{826D715 1-8D99-434 B-8540-082 B8C2AE556}
Key Found : HKLM\SOFTWARE\Classes\CLSI D\{85F5CF9 5-EC8F-49F C-BB3F-38C 79455CBA2}
Key Found : HKLM\SOFTWARE\Classes\CLSI D\{A531D99 C-5A22-449 B-83DA-872 725C6D0ED}
Key Found : HKLM\SOFTWARE\Classes\CLSI D\{D4027C7 F-154A-406 6-A1AD-424 3D8127440}
Key Found : HKLM\SOFTWARE\Classes\CLSI D\{EF99BD3 2-C1FB-11D 2-892F-009 0271D4F88}
Key Found : HKLM\SOFTWARE\Classes\Gene ricAskTool bar.Toolba rWnd
Key Found : HKLM\SOFTWARE\Classes\Gene ricAskTool bar.Toolba rWnd.1
Key Found : HKLM\Software\Classes\Inst aller\Feat ures\A28B4 D68DEBAA24 4EB686953B 7074FEF
Key Found : HKLM\Software\Classes\Inst aller\Prod ucts\A28B4 D68DEBAA24 4EB686953B 7074FEF
Key Found : HKLM\SOFTWARE\Classes\Inte rface\{019 4532A-A99C -4337-937E -2A452C895 7BE}
Key Found : HKLM\SOFTWARE\Classes\Inte rface\{66E EF543-A9AC -4A9D-AA3C -1ED148AC8 EEE}
Key Found : HKLM\SOFTWARE\Classes\Inte rface\{66E EF543-A9AC -4A9D-AA3C -1ED148AC8 FFE}
Key Found : HKLM\SOFTWARE\Classes\Inte rface\{6C4 34537-053E -486D-B62A -160059D9D 456}
Key Found : HKLM\SOFTWARE\Classes\Inte rface\{91C F619A-4686 -4CA4-9232 -3B2E6B63A A92}
Key Found : HKLM\SOFTWARE\Classes\Inte rface\{AC7 1B60E-94C9 -4EDE-BA46 -E146747BB 67E}
Key Found : HKLM\SOFTWARE\Classes\S
Key Found : HKLM\SOFTWARE\Classes\Type Lib\{11549 FE4-7C5A-4 C17-9FC3-5 6FC5162A99 4}
Key Found : HKLM\SOFTWARE\Classes\Type Lib\{2996F 0E7-292B-4 CAE-893F-4 7B8B1C05B5 6}
Key Found : HKLM\SOFTWARE\Classes\Type Lib\{92E50 39E-FF1E-4 AFB-8F24-8 7592D20C38 3}
Key Found : HKLM\Software\Description
Key Found : HKLM\SOFTWARE\Microsoft\In ternet Explorer\Low Rights\ElevationPolicy\{A5 AA24EA-11B 8-4113-95A E-9ED71DEA F12A}
Key Found : HKLM\SOFTWARE\Microsoft\Wi ndows\Curr entVersion \App Management\ARPCache\{86D4B 82A-ABED-4 42A-BE86-9 6357B70F4F E}
Key Found : HKLM\SOFTWARE\Microsoft\Wi ndows\Curr entVersion \App Management\ARPCache\alotAp pbar
Key Found : HKLM\SOFTWARE\Microsoft\Wi ndows\Curr entVersion \Explorer\ Browser Helper Objects\{02478D38-C3F9-4EF B-9B51-769 5ECA05670}
Key Found : HKLM\SOFTWARE\Microsoft\Wi ndows\Curr entVersion \Explorer\ Browser Helper Objects\{85F5CF95-EC8F-49F C-BB3F-38C 79455CBA2}
Key Found : HKLM\SOFTWARE\Microsoft\Wi ndows\Curr entVersion \Explorer\ Browser Helper Objects\{D4027C7F-154A-406 6-A1AD-424 3D8127440}
Key Found : HKLM\SOFTWARE\Microsoft\Wi ndows\Curr entVersion \Ext\PreAp proved\{02 478D38-C3F 9-4EFB-9B5 1-7695ECA0 5670}
Key Found : HKLM\SOFTWARE\Microsoft\Wi ndows\Curr entVersion \Ext\PreAp proved\{EF 99BD32-C1F B-11D2-892 F-0090271D 4F88}
Key Found : HKLM\Software\Microsoft\Wi ndows\Curr entVersion \Installer \UpgradeCo des\F92812 3A03964954 9966D4C29D 35B1C9
Key Found : HKLM\Software\Microsoft\Wi ndows\Curr entVersion \Installer \UserData\ S-1-5-18\C omponents\ 261F213D1F 55267499B1 F87D0CC3BC F7
Key Found : HKLM\Software\Microsoft\Wi ndows\Curr entVersion \Installer \UserData\ S-1-5-18\C omponents\ 741B4ADF27 2764647900 22C965AB6D A8
Key Found : HKLM\Software\Microsoft\Wi ndows\Curr entVersion \Installer \UserData\ S-1-5-18\C omponents\ 7DE196B101 95F5647A2B 21B761F3DE 01
Key Found : HKLM\Software\Microsoft\Wi ndows\Curr entVersion \Installer \UserData\ S-1-5-18\C omponents\ 9D4F584936 7142E4685E D8C25E44C5 ED
Key Found : HKLM\Software\Microsoft\Wi ndows\Curr entVersion \Installer \UserData\ S-1-5-18\C omponents\ A5875B0437 2C19545BEB 90D4D606C4 72
Key Found : HKLM\Software\Microsoft\Wi ndows\Curr entVersion \Installer \UserData\ S-1-5-18\C omponents\ A876D9E80B 896EC44A86 20248CC792 96
Key Found : HKLM\Software\Microsoft\Wi ndows\Curr entVersion \Installer \UserData\ S-1-5-18\C omponents\ B66FFAB725 B92594C986 DE826A8678 88
Key Found : HKLM\Software\Microsoft\Wi ndows\Curr entVersion \Installer \UserData\ S-1-5-18\P roducts\A2 8B4D68DEBA A244EB6869 53B7074FEF
Key Found : HKLM\SOFTWARE\Microsoft\Wi ndows\Curr entVersion \Uninstall \{86D4B82A -ABED-442A -BE86-9635 7B70F4FE}
Key Found : HKLM\SOFTWARE\Microsoft\Wi ndows\Curr entVersion \Uninstall \alotAppba r
Value Found : HKCU\Software\Microsoft\In ternet Explorer\Toolbar\WebBrowse r [{D4027C7F-154A-4066-A1AD- 4243D81274 40}]
Value Found : HKLM\SOFTWARE\Microsoft\In ternet Explorer\Toolbar [{A531D99C-5A22-449B-83DA- 872725C6D0 ED}]
Value Found : HKLM\SOFTWARE\Microsoft\In ternet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD- 4243D81274 40}]
Value Found : HKLM\SOFTWARE\Microsoft\In ternet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F- 0090271D4F 88}]
***** [ Browsers ] *****
-\\ Internet Explorer v8.0.6001.18702
-\\ Google Chrome v31.0.1650.63
[ File : C:\Documents and Settings\jfischer\Local Settings\Application Data\Google\Chrome\User Data\Default\preferences ]
[ File : C:\Documents and Settings\Administrator.SIL VER\Local Settings\Application Data\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [7936 octets] - [17/12/2013 10:13:41]
########## EOF - C:\AdwCleaner\AdwCleaner[R 0].txt - [7996 octets] ##########
IMG-20131217-111907-453.jpg
I have scanned this computer and it is scanning clean after I used; adwcleaner, malwarebytes, malwarebytes rootkit scanner, and rogue killer.
I am still noticing that since this began the user has not been able to attach pictures from his my doc folder. I went in and reset his permissions and tried to stop his antivirus and send and it did not correct the issue. I had another post some time back where the Outlook issue occurred with another user
The system is an Windows XP sp3 and I am including the adwcleaner log and will attach a screen shot of the replicating my computer deal the name of it is "32788R22FWJFW"...
# AdwCleaner v3.015 - Report created 17/12/2013 at 10:13:41
# Updated 10/12/2013 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : jfischer - QTYMANAGER
# Running from : E:\adwcleaner.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Found C:\Documents and Settings\Administrator.SIL
Folder Found C:\Documents and Settings\jfischer\Applicat
Folder Found C:\Documents and Settings\jfischer\Local Settings\Application Data\AskToolbar
Folder Found C:\Documents and Settings\jfischer\Local Settings\Application Data\PackageAware
Folder Found C:\Program Files\alotappbar
Folder Found C:\Program Files\Ask.com
Folder Found C:\WINDOWS\installer\{86d4
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\alotAppbar
Key Found : HKCU\Software\AppDataLow\A
Key Found : HKCU\Software\Ask.com
Key Found : HKCU\Software\AskToolbar
Key Found : HKCU\Software\Microsoft\In
Key Found : HKCU\Software\Microsoft\In
Key Found : HKCU\Software\Microsoft\Wi
Key Found : HKCU\Software\Microsoft\Wi
Key Found : HKCU\Software\Microsoft\Wi
Key Found : HKCU\Software\Microsoft\Wi
Key Found : HKCU\Software\Microsoft\Wi
Key Found : HKCU\Software\Microsoft\Wi
Key Found : HKCU\Software\Microsoft\Wi
Key Found : HKCU\Software\Microsoft\Wi
Key Found : HKCU\Software\Microsoft\Wi
Key Found : HKCU\Software\Microsoft\Wi
Key Found : HKCU\Software\Microsoft\Wi
Key Found : HKCU\Software\Microsoft\Wi
Key Found : HKCU\Software\YahooPartner
Key Found : HKLM\SOFTWARE\Classes\AppI
Key Found : HKLM\SOFTWARE\Classes\AppI
Key Found : HKLM\SOFTWARE\Classes\AppI
Key Found : HKLM\SOFTWARE\Classes\AppI
Key Found : HKLM\SOFTWARE\Classes\CLSI
Key Found : HKLM\SOFTWARE\Classes\CLSI
Key Found : HKLM\SOFTWARE\Classes\CLSI
Key Found : HKLM\SOFTWARE\Classes\CLSI
Key Found : HKLM\SOFTWARE\Classes\CLSI
Key Found : HKLM\SOFTWARE\Classes\CLSI
Key Found : HKLM\SOFTWARE\Classes\CLSI
Key Found : HKLM\SOFTWARE\Classes\CLSI
Key Found : HKLM\SOFTWARE\Classes\CLSI
Key Found : HKLM\SOFTWARE\Classes\Gene
Key Found : HKLM\SOFTWARE\Classes\Gene
Key Found : HKLM\Software\Classes\Inst
Key Found : HKLM\Software\Classes\Inst
Key Found : HKLM\SOFTWARE\Classes\Inte
Key Found : HKLM\SOFTWARE\Classes\Inte
Key Found : HKLM\SOFTWARE\Classes\Inte
Key Found : HKLM\SOFTWARE\Classes\Inte
Key Found : HKLM\SOFTWARE\Classes\Inte
Key Found : HKLM\SOFTWARE\Classes\Inte
Key Found : HKLM\SOFTWARE\Classes\S
Key Found : HKLM\SOFTWARE\Classes\Type
Key Found : HKLM\SOFTWARE\Classes\Type
Key Found : HKLM\SOFTWARE\Classes\Type
Key Found : HKLM\Software\Description
Key Found : HKLM\SOFTWARE\Microsoft\In
Key Found : HKLM\SOFTWARE\Microsoft\Wi
Key Found : HKLM\SOFTWARE\Microsoft\Wi
Key Found : HKLM\SOFTWARE\Microsoft\Wi
Key Found : HKLM\SOFTWARE\Microsoft\Wi
Key Found : HKLM\SOFTWARE\Microsoft\Wi
Key Found : HKLM\SOFTWARE\Microsoft\Wi
Key Found : HKLM\SOFTWARE\Microsoft\Wi
Key Found : HKLM\Software\Microsoft\Wi
Key Found : HKLM\Software\Microsoft\Wi
Key Found : HKLM\Software\Microsoft\Wi
Key Found : HKLM\Software\Microsoft\Wi
Key Found : HKLM\Software\Microsoft\Wi
Key Found : HKLM\Software\Microsoft\Wi
Key Found : HKLM\Software\Microsoft\Wi
Key Found : HKLM\Software\Microsoft\Wi
Key Found : HKLM\Software\Microsoft\Wi
Key Found : HKLM\SOFTWARE\Microsoft\Wi
Key Found : HKLM\SOFTWARE\Microsoft\Wi
Value Found : HKCU\Software\Microsoft\In
Value Found : HKLM\SOFTWARE\Microsoft\In
Value Found : HKLM\SOFTWARE\Microsoft\In
Value Found : HKLM\SOFTWARE\Microsoft\In
***** [ Browsers ] *****
-\\ Internet Explorer v8.0.6001.18702
-\\ Google Chrome v31.0.1650.63
[ File : C:\Documents and Settings\jfischer\Local Settings\Application Data\Google\Chrome\User Data\Default\preferences ]
[ File : C:\Documents and Settings\Administrator.SIL
*************************
AdwCleaner[R0].txt - [7936 octets] - [17/12/2013 10:13:41]
########## EOF - C:\AdwCleaner\AdwCleaner[R
IMG-20131217-111907-453.jpg
ASKER
I thought about that.... and it may be what I end up doing to get those permissions to reset.. even when I search online for any similar viruses I don't see any...
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
If restore works, rescan with Malwarebytes antimalware and Adwcleaner.