Removed: 799d.exe, 977o.dll, tmp.exe, 9bee.dll, ms.job (trojan Adload)

Malware: qd.exe

Removed: C:\WINDOWS\system32\799d.exe
C:\WINDOWS\system32\977o.dll
C:\WINDOWS\Temp\tmp.exe
C:\WINDOWS\Tasks\ms.job
C:\WINDOWS\system32\9bee.dll

—————————————————————————————————————————-
Detected by UnHackMe:

Item Name: {C15134ED-31C1-4b17-B04E-FFFAB993EFA2}
Author: Beijing Angels Technology ltd.
Related File: C:\WINDOWS\SYSTEM32\977O.DLL
Type: Browser Helper Objects

Item Name: OSS
Author:
Related File: C:\WINDOWS\system32\799d.exe
Type: Auto Services

Item Name: home.lnk
Author: Unknown
Related File: C:\WINDOWS\TEMP\TMP.EXE
Type: Common Startup Folder

Item Name: 799d.exe
Author: Unknown
Related File: C:\WINDOWS\SYSTEM32\799D.EXE
Type: Running Processes

The object is detected manually:
C:\WINDOWS\Tasks\ms.job
Content jobs (run every 2 hours):
rundll32 C:\WINDOWS\system32\9bee.dll,Always

Removal Results: Success
Number of reboot: 1
—————————————————————————————————————————-
Classification:

Antivirus Version Last Update Result
F-Secure 9.0.15370.0 2010.05.19 -
Kaspersky 7.0.0.125 2010.05.20 -
Microsoft 1.5802 2010.05.20 TrojanDownloader:Win32/Adload.L
NOD32 5130 2010.05.19 a variant of Win32/Adware.WSearch.AD

—————————————————————————————————————————-
Additional information
File size: 499712 bytes
MD5 : df8f979622eb79ee5d7fb28fe227dca7
SHA1 : 0e13771313acc615de8e6c7a28887a17f380c480
SHA256: ac5e1628317daf1cdc7178ee98a58742c5c27a11cd7fdfca02d2c3bd43f3f400
—————————————————————————————————————————-
Installation
When the program is executed, it creates the following registry subkeys and values:

———————————-
Keys added:29
———————————-
HKLM\Software\Classes\AppID\BHO.DLL
HKLM\Software\Classes\AppID\{53738F3D-33DE-4bf3-8F3F-0FDA9BBE7121}
HKLM\Software\Classes\CLSID\{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}
HKLM\Software\Classes\CLSID\{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}\InprocServer32
HKLM\Software\Classes\CLSID\{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}\ProgID
HKLM\Software\Classes\CLSID\{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}\Programmable
HKLM\Software\Classes\CLSID\{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}\TypeLib
HKLM\Software\Classes\CLSID\{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}\VersionIndependentProgID
HKLM\Software\Classes\Interface\{3D91005B-09EB-43B9-AEB2-31DD4C587447}
HKLM\Software\Classes\Interface\{3D91005B-09EB-43B9-AEB2-31DD4C587447}\ProxyStubClsid
HKLM\Software\Classes\Interface\{3D91005B-09EB-43B9-AEB2-31DD4C587447}\ProxyStubClsid32
HKLM\Software\Classes\Interface\{3D91005B-09EB-43B9-AEB2-31DD4C587447}\TypeLib
HKLM\Software\Classes\TypeLib\{53738F3D-33DE-4BF3-8F3F-0FDA9BBE7121}
HKLM\Software\Classes\TypeLib\{53738F3D-33DE-4BF3-8F3F-0FDA9BBE7121}\1.0
HKLM\Software\Classes\TypeLib\{53738F3D-33DE-4BF3-8F3F-0FDA9BBE7121}\1.0\0
HKLM\Software\Classes\TypeLib\{53738F3D-33DE-4BF3-8F3F-0FDA9BBE7121}\1.0\0\win32
HKLM\Software\Classes\TypeLib\{53738F3D-33DE-4BF3-8F3F-0FDA9BBE7121}\1.0\FLAGS
HKLM\Software\Classes\TypeLib\{53738F3D-33DE-4BF3-8F3F-0FDA9BBE7121}\1.0\HELPDIR
HKLM\Software\Classes\BHO.FunPlayer
HKLM\Software\Classes\BHO.FunPlayer\CLSID
HKLM\Software\Classes\BHO.FunPlayer\CurVer
HKLM\Software\Classes\BHO.FunPlayer.1
HKLM\Software\Classes\BHO.FunPlayer.1\CLSID
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}
HKLM\System\CurrentControlSet\Enum\Root\LEGACY_OSS
HKLM\System\CurrentControlSet\Enum\Root\LEGACY_OSS\0000
HKLM\System\CurrentControlSet\Services\Eventlog\Application\OSS
HKLM\System\CurrentControlSet\Services\OSS
HKLM\System\CurrentControlSet\Services\OSS\Security

———————————-
Values added:40
———————————-
HKLM\Software\Classes\AppID\BHO.DLL\AppID: “”
HKLM\Software\Classes\AppID\{53738F3D-33DE-4bf3-8F3F-0FDA9BBE7121}\: “BHO”
HKLM\Software\Classes\CLSID\{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}\VersionIndependentProgID\: “BHO.FunPlayer”
HKLM\Software\Classes\CLSID\{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}\TypeLib\: “{53738F3D-33DE-4BF3-8F3F-0FDA9BBE7121}”
HKLM\Software\Classes\CLSID\{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}\ProgID\: “BHO.FunPlayer.1″
HKLM\Software\Classes\CLSID\{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}\InprocServer32\: “C:\WINDOWS\system32\977o.dll”
HKLM\Software\Classes\CLSID\{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}\InprocServer32\ThreadingModel: “apartment”
HKLM\Software\Classes\CLSID\{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}\: “CFunPlayer Object”
HKLM\Software\Classes\CLSID\{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}\AppID: “”
HKLM\Software\Classes\Interface\{3D91005B-09EB-43B9-AEB2-31DD4C587447}\TypeLib\: “{53738F3D-33DE-4BF3-8F3F-0FDA9BBE7121}”
HKLM\Software\Classes\Interface\{3D91005B-09EB-43B9-AEB2-31DD4C587447}\TypeLib\Version: “1.0″
HKLM\Software\Classes\Interface\{3D91005B-09EB-43B9-AEB2-31DD4C587447}\ProxyStubClsid32\: “{00020424-0000-0000-C000-000000000046}”
HKLM\Software\Classes\Interface\{3D91005B-09EB-43B9-AEB2-31DD4C587447}\ProxyStubClsid\: “{00020424-0000-0000-C000-000000000046}”
HKLM\Software\Classes\Interface\{3D91005B-09EB-43B9-AEB2-31DD4C587447}\: “IFunPlayer”
HKLM\Software\Classes\TypeLib\{53738F3D-33DE-4BF3-8F3F-0FDA9BBE7121}\1.0\0\win32\: “C:\WINDOWS\system32\977o.dll”
HKLM\Software\Classes\TypeLib\{53738F3D-33DE-4BF3-8F3F-0FDA9BBE7121}\1.0\HELPDIR\: “C:\WINDOWS\system32\”
HKLM\Software\Classes\TypeLib\{53738F3D-33DE-4BF3-8F3F-0FDA9BBE7121}\1.0\FLAGS\: “0″
HKLM\Software\Classes\TypeLib\{53738F3D-33DE-4BF3-8F3F-0FDA9BBE7121}\1.0\: “BHO 1.0 Type Library”
HKLM\Software\Classes\BHO.FunPlayer\CurVer\: “BHO.FunPlayer.1″
HKLM\Software\Classes\BHO.FunPlayer\CLSID\: “{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}”
HKLM\Software\Classes\BHO.FunPlayer\: “CFunPlayer Object”
HKLM\Software\Classes\BHO.FunPlayer.1\CLSID\: “{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}”
HKLM\Software\Classes\BHO.FunPlayer.1\: “CFunPlayer Object”
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}\: “Generic BHO”
HKLM\System\CurrentControlSet\Enum\Root\LEGACY_OSS\0000\Service: “OSS”
HKLM\System\CurrentControlSet\Enum\Root\LEGACY_OSS\0000\Legacy: 0×00000001
HKLM\System\CurrentControlSet\Enum\Root\LEGACY_OSS\0000\ConfigFlags: 0×00000000
HKLM\System\CurrentControlSet\Enum\Root\LEGACY_OSS\0000\Class: “LegacyDriver”
HKLM\System\CurrentControlSet\Enum\Root\LEGACY_OSS\0000\ClassGUID: “{8ECC055D-047F-11D1-A537-0000F8753ED1}”
HKLM\System\CurrentControlSet\Enum\Root\LEGACY_OSS\0000\DeviceDesc: “OSS”
HKLM\System\CurrentControlSet\Enum\Root\LEGACY_OSS\NextInstance: 0×00000001
HKLM\System\CurrentControlSet\Services\Eventlog\Application\OSS\EventMessageFile: “C:\WINDOWS\system32\799d.exe”
HKLM\System\CurrentControlSet\Services\Eventlog\Application\OSS\TypesSupported: 0×00000007
HKLM\System\CurrentControlSet\Services\OSS\Security\Security: 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 0B 00 00 00 00 00 18 00 FD 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00
HKLM\System\CurrentControlSet\Services\OSS\Type: 0×00000010
HKLM\System\CurrentControlSet\Services\OSS\Start: 0×00000002
HKLM\System\CurrentControlSet\Services\OSS\ErrorControl: 0×00000001
HKLM\System\CurrentControlSet\Services\OSS\ImagePath: “C:\WINDOWS\system32\799d.exe”
HKLM\System\CurrentControlSet\Services\OSS\DisplayName: “OSS”
HKLM\System\CurrentControlSet\Services\OSS\ObjectName: “LocalSystem”

———————————-
Values modified:4
———————————-
(-) HKLM\System\CurrentControlSet\Services\Eventlog\Application\Sources: ‘WSH WMIAdapter WmdmPmSN WinMgmt Winlogon Windows Product Activation Windows 3.1 Migration WebClient VSS vmtools VBRuntime Userinit Userenv Tlntsvr SysmonLog Starter SpoolerCtrs Software Restriction Policies Software Installation SecurityCenter SclgNtfy SceSrv SceCli safrslv SAFrdms RPC Remote Assistance PerfProc PerfOS PerfNet Perfmon Perflib PerfDisk Perfctrs Offline Files Oakley ntbackup MSSQLSERVER/MSDE MSSHA MsiInstaller MSDTC Client MSDTC mnmsrvc Microsoft H.323 Telephony Service Provider Microsoft (R) Visual C# 2005 Compiler LoadPerf HelpSvc Folder Redirection File Deployment EventSystem ESENT DrWatson Dot3Svc DiskQuota crypt32 COM+ COM Ci Chkdsk AutoEnrollment Autochk ASP.NET 2.0.50727.0 Application Management Application Hang Application Error .NET Runtime Optimization Service .NET Runtime 2.0 Error Reporting .NET Runtime Application’
(+) HKLM\System\CurrentControlSet\Services\Eventlog\Application\Sources: ‘WSH WMIAdapter WmdmPmSN WinMgmt Winlogon Windows Product Activation Windows 3.1 Migration WebClient VSS vmtools VBRuntime Userinit Userenv Tlntsvr SysmonLog Starter SpoolerCtrs Software Restriction Policies Software Installation SecurityCenter SclgNtfy SceSrv SceCli safrslv SAFrdms RPC Remote Assistance PerfProc PerfOS PerfNet Perfmon Perflib PerfDisk Perfctrs OSS Offline Files Oakley ntbackup MSSQLSERVER/MSDE MSSHA MsiInstaller MSDTC Client MSDTC mnmsrvc Microsoft H.323 Telephony Service Provider Microsoft (R) Visual C# 2005 Compiler LoadPerf HelpSvc Folder Redirection File Deployment EventSystem ESENT DrWatson Dot3Svc DiskQuota crypt32 COM+ COM Ci Chkdsk AutoEnrollment Autochk ASP.NET 2.0.50727.0 Application Management Application Hang Application Error .NET Runtime Optimization Service .NET Runtime 2.0 Error Reporting .NET Runtime Application’
(-) HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cookies: “C:\Documents and Settings\Administrator\Cookies”
(+) HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cookies: “C:\Documents and Settings\LocalService\Cookies”
(+) HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache: “C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files”
(+) HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\History: “C:\Documents and Settings\LocalService\Local Settings\History”

———————————-
Files added:19
———————————-
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\home.lnk
C:\WINDOWS\system32\-54-16133
C:\WINDOWS\system32\799d.exe
C:\WINDOWS\system32\977o.dll
C:\WINDOWS\system32\9bee.dll
C:\WINDOWS\Tasks\ms.job
C:\WINDOWS\Temp\Cookies\index.dat
C:\WINDOWS\Temp\History\History.IE5\desktop.ini
C:\WINDOWS\Temp\History\History.IE5\index.dat
C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\0G7T6J1R\desktop.ini
C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\9IMAVVB8\desktop.ini
C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\desktop.ini
C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\G64GHMYZ\desktop.ini
C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\index.dat
C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\MRW01RXI\desktop.ini
C:\WINDOWS\Temp\tmp.exe
C:\WINDOWS\1b6u.bmp
C:\WINDOWS\91bd.exe
C:\WINDOWS\f91d.flv

———————————-
Folders added:12
———————————-
C:\Documents and Settings\Administrator\Local Settings\Temp\h8nil4o8
C:\Documents and Settings\All Users\Application Data\t
C:\Documents and Settings\All Users\Application Data\t\ad
C:\WINDOWS\Temp\Cookies
C:\WINDOWS\Temp\History
C:\WINDOWS\Temp\History\History.IE5
C:\WINDOWS\Temp\Temporary Internet Files
C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5
C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\0G7T6J1R
C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\9IMAVVB8
C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\G64GHMYZ
C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\MRW01RXI

———————————-
Total changes:104
———————————-

—————————————————————————————————————————-
Recommended software:
UnHackMe anti-rootkit and anti-malware
http://www.unhackme.com
RegRun Security Suite (Good choice for removal and protection)
http://www.regrun.com

Fix it immediately!

Free Download

UnHackMe removes malware invisible for your antivirus!

Leave a Reply