Removed: 799d.exe, 977o.dll, tmp.exe, 9bee.dll, ms.job (trojan Adload)

Dmitry Sokolov recommends UnHackMe!


UnHackMe quickly removes pop-up ads, search redirecting, browser hijack, spyware, keyloggers, PC slowdown issues. Download Now!

Download free e-book [PDF]: "How to Easily Remove Malware with UnHackMe"

Join us on Facebook
Click to Download
Solved! The issue has been fixed!
5 Stars (5 / 5)


Share This:

Malware: qd.exe

Removed: C:\WINDOWS\system32\799d.exe
C:\WINDOWS\system32\977o.dll
C:\WINDOWS\Temp\tmp.exe
C:\WINDOWS\Tasks\ms.job
C:\WINDOWS\system32\9bee.dll

—————————————————————————————————————————-
Detected by UnHackMe:

Item Name: {C15134ED-31C1-4b17-B04E-FFFAB993EFA2}
Author: Beijing Angels Technology ltd.
Related File: C:\WINDOWS\SYSTEM32\977O.DLL
Type: Browser Helper Objects


Your Vote?
0 0

Item Name: OSS
Author:
Related File: C:\WINDOWS\system32\799d.exe
Type: Auto Services

Item Name: home.lnk
Author: Unknown
Related File: C:\WINDOWS\TEMP\TMP.EXE
Type: Common Startup Folder

Item Name: 799d.exe
Author: Unknown
Related File: C:\WINDOWS\SYSTEM32\799D.EXE
Type: Running Processes

The object is detected manually:
C:\WINDOWS\Tasks\ms.job
Content jobs (run every 2 hours):
rundll32 C:\WINDOWS\system32\9bee.dll,Always

Removal Results: Success
Number of reboot: 1
—————————————————————————————————————————-
Classification:

Antivirus Version Last Update Result
F-Secure 9.0.15370.0 2010.05.19 -
Kaspersky 7.0.0.125 2010.05.20 -
Microsoft 1.5802 2010.05.20 TrojanDownloader:Win32/Adload.L
NOD32 5130 2010.05.19 a variant of Win32/Adware.WSearch.AD

—————————————————————————————————————————-
Additional information
File size: 499712 bytes
MD5 : df8f979622eb79ee5d7fb28fe227dca7
SHA1 : 0e13771313acc615de8e6c7a28887a17f380c480
SHA256: ac5e1628317daf1cdc7178ee98a58742c5c27a11cd7fdfca02d2c3bd43f3f400
—————————————————————————————————————————-
Installation
When the program is executed, it creates the following registry subkeys and values:

———————————-
Keys added:29
———————————-
HKLM\Software\Classes\AppID\BHO.DLL
HKLM\Software\Classes\AppID\{53738F3D-33DE-4bf3-8F3F-0FDA9BBE7121}
HKLM\Software\Classes\CLSID\{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}
HKLM\Software\Classes\CLSID\{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}\InprocServer32
HKLM\Software\Classes\CLSID\{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}\ProgID
HKLM\Software\Classes\CLSID\{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}\Programmable
HKLM\Software\Classes\CLSID\{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}\TypeLib
HKLM\Software\Classes\CLSID\{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}\VersionIndependentProgID
HKLM\Software\Classes\Interface\{3D91005B-09EB-43B9-AEB2-31DD4C587447}
HKLM\Software\Classes\Interface\{3D91005B-09EB-43B9-AEB2-31DD4C587447}\ProxyStubClsid
HKLM\Software\Classes\Interface\{3D91005B-09EB-43B9-AEB2-31DD4C587447}\ProxyStubClsid32
HKLM\Software\Classes\Interface\{3D91005B-09EB-43B9-AEB2-31DD4C587447}\TypeLib
HKLM\Software\Classes\TypeLib\{53738F3D-33DE-4BF3-8F3F-0FDA9BBE7121}
HKLM\Software\Classes\TypeLib\{53738F3D-33DE-4BF3-8F3F-0FDA9BBE7121}\1.0
HKLM\Software\Classes\TypeLib\{53738F3D-33DE-4BF3-8F3F-0FDA9BBE7121}\1.0\0
HKLM\Software\Classes\TypeLib\{53738F3D-33DE-4BF3-8F3F-0FDA9BBE7121}\1.0\0\win32
HKLM\Software\Classes\TypeLib\{53738F3D-33DE-4BF3-8F3F-0FDA9BBE7121}\1.0\FLAGS
HKLM\Software\Classes\TypeLib\{53738F3D-33DE-4BF3-8F3F-0FDA9BBE7121}\1.0\HELPDIR
HKLM\Software\Classes\BHO.FunPlayer
HKLM\Software\Classes\BHO.FunPlayer\CLSID
HKLM\Software\Classes\BHO.FunPlayer\CurVer
HKLM\Software\Classes\BHO.FunPlayer.1
HKLM\Software\Classes\BHO.FunPlayer.1\CLSID
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}
HKLM\System\CurrentControlSet\Enum\Root\LEGACY_OSS
HKLM\System\CurrentControlSet\Enum\Root\LEGACY_OSS\0000
HKLM\System\CurrentControlSet\Services\Eventlog\Application\OSS
HKLM\System\CurrentControlSet\Services\OSS
HKLM\System\CurrentControlSet\Services\OSS\Security

———————————-
Values added:40
———————————-
HKLM\Software\Classes\AppID\BHO.DLL\AppID: “”
HKLM\Software\Classes\AppID\{53738F3D-33DE-4bf3-8F3F-0FDA9BBE7121}\: “BHO”
HKLM\Software\Classes\CLSID\{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}\VersionIndependentProgID\: “BHO.FunPlayer”
HKLM\Software\Classes\CLSID\{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}\TypeLib\: “{53738F3D-33DE-4BF3-8F3F-0FDA9BBE7121}”
HKLM\Software\Classes\CLSID\{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}\ProgID\: “BHO.FunPlayer.1″
HKLM\Software\Classes\CLSID\{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}\InprocServer32\: “C:\WINDOWS\system32\977o.dll”
HKLM\Software\Classes\CLSID\{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}\InprocServer32\ThreadingModel: “apartment”
HKLM\Software\Classes\CLSID\{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}\: “CFunPlayer Object”
HKLM\Software\Classes\CLSID\{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}\AppID: “”
HKLM\Software\Classes\Interface\{3D91005B-09EB-43B9-AEB2-31DD4C587447}\TypeLib\: “{53738F3D-33DE-4BF3-8F3F-0FDA9BBE7121}”
HKLM\Software\Classes\Interface\{3D91005B-09EB-43B9-AEB2-31DD4C587447}\TypeLib\Version: “1.0″
HKLM\Software\Classes\Interface\{3D91005B-09EB-43B9-AEB2-31DD4C587447}\ProxyStubClsid32\: “{00020424-0000-0000-C000-000000000046}”
HKLM\Software\Classes\Interface\{3D91005B-09EB-43B9-AEB2-31DD4C587447}\ProxyStubClsid\: “{00020424-0000-0000-C000-000000000046}”
HKLM\Software\Classes\Interface\{3D91005B-09EB-43B9-AEB2-31DD4C587447}\: “IFunPlayer”
HKLM\Software\Classes\TypeLib\{53738F3D-33DE-4BF3-8F3F-0FDA9BBE7121}\1.0\0\win32\: “C:\WINDOWS\system32\977o.dll”
HKLM\Software\Classes\TypeLib\{53738F3D-33DE-4BF3-8F3F-0FDA9BBE7121}\1.0\HELPDIR\: “C:\WINDOWS\system32\”
HKLM\Software\Classes\TypeLib\{53738F3D-33DE-4BF3-8F3F-0FDA9BBE7121}\1.0\FLAGS\: “0″
HKLM\Software\Classes\TypeLib\{53738F3D-33DE-4BF3-8F3F-0FDA9BBE7121}\1.0\: “BHO 1.0 Type Library”
HKLM\Software\Classes\BHO.FunPlayer\CurVer\: “BHO.FunPlayer.1″
HKLM\Software\Classes\BHO.FunPlayer\CLSID\: “{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}”
HKLM\Software\Classes\BHO.FunPlayer\: “CFunPlayer Object”
HKLM\Software\Classes\BHO.FunPlayer.1\CLSID\: “{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}”
HKLM\Software\Classes\BHO.FunPlayer.1\: “CFunPlayer Object”
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C15134ED-31C1-4b17-B04E-FFFAB993EFA2}\: “Generic BHO”
HKLM\System\CurrentControlSet\Enum\Root\LEGACY_OSS\0000\Service: “OSS”
HKLM\System\CurrentControlSet\Enum\Root\LEGACY_OSS\0000\Legacy: 0×00000001
HKLM\System\CurrentControlSet\Enum\Root\LEGACY_OSS\0000\ConfigFlags: 0×00000000
HKLM\System\CurrentControlSet\Enum\Root\LEGACY_OSS\0000\Class: “LegacyDriver”
HKLM\System\CurrentControlSet\Enum\Root\LEGACY_OSS\0000\ClassGUID: “{8ECC055D-047F-11D1-A537-0000F8753ED1}”
HKLM\System\CurrentControlSet\Enum\Root\LEGACY_OSS\0000\DeviceDesc: “OSS”
HKLM\System\CurrentControlSet\Enum\Root\LEGACY_OSS\NextInstance: 0×00000001
HKLM\System\CurrentControlSet\Services\Eventlog\Application\OSS\EventMessageFile: “C:\WINDOWS\system32\799d.exe”
HKLM\System\CurrentControlSet\Services\Eventlog\Application\OSS\TypesSupported: 0×00000007
HKLM\System\CurrentControlSet\Services\OSS\Security\Security: 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 0B 00 00 00 00 00 18 00 FD 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00
HKLM\System\CurrentControlSet\Services\OSS\Type: 0×00000010
HKLM\System\CurrentControlSet\Services\OSS\Start: 0×00000002
HKLM\System\CurrentControlSet\Services\OSS\ErrorControl: 0×00000001
HKLM\System\CurrentControlSet\Services\OSS\ImagePath: “C:\WINDOWS\system32\799d.exe”
HKLM\System\CurrentControlSet\Services\OSS\DisplayName: “OSS”
HKLM\System\CurrentControlSet\Services\OSS\ObjectName: “LocalSystem”

———————————-
Values modified:4
———————————-
(-) HKLM\System\CurrentControlSet\Services\Eventlog\Application\Sources: ‘WSH WMIAdapter WmdmPmSN WinMgmt Winlogon Windows Product Activation Windows 3.1 Migration WebClient VSS vmtools VBRuntime Userinit Userenv Tlntsvr SysmonLog Starter SpoolerCtrs Software Restriction Policies Software Installation SecurityCenter SclgNtfy SceSrv SceCli safrslv SAFrdms RPC Remote Assistance PerfProc PerfOS PerfNet Perfmon Perflib PerfDisk Perfctrs Offline Files Oakley ntbackup MSSQLSERVER/MSDE MSSHA MsiInstaller MSDTC Client MSDTC mnmsrvc Microsoft H.323 Telephony Service Provider Microsoft (R) Visual C# 2005 Compiler LoadPerf HelpSvc Folder Redirection File Deployment EventSystem ESENT DrWatson Dot3Svc DiskQuota crypt32 COM+ COM Ci Chkdsk AutoEnrollment Autochk ASP.NET 2.0.50727.0 Application Management Application Hang Application Error .NET Runtime Optimization Service .NET Runtime 2.0 Error Reporting .NET Runtime Application’
(+) HKLM\System\CurrentControlSet\Services\Eventlog\Application\Sources: ‘WSH WMIAdapter WmdmPmSN WinMgmt Winlogon Windows Product Activation Windows 3.1 Migration WebClient VSS vmtools VBRuntime Userinit Userenv Tlntsvr SysmonLog Starter SpoolerCtrs Software Restriction Policies Software Installation SecurityCenter SclgNtfy SceSrv SceCli safrslv SAFrdms RPC Remote Assistance PerfProc PerfOS PerfNet Perfmon Perflib PerfDisk Perfctrs OSS Offline Files Oakley ntbackup MSSQLSERVER/MSDE MSSHA MsiInstaller MSDTC Client MSDTC mnmsrvc Microsoft H.323 Telephony Service Provider Microsoft (R) Visual C# 2005 Compiler LoadPerf HelpSvc Folder Redirection File Deployment EventSystem ESENT DrWatson Dot3Svc DiskQuota crypt32 COM+ COM Ci Chkdsk AutoEnrollment Autochk ASP.NET 2.0.50727.0 Application Management Application Hang Application Error .NET Runtime Optimization Service .NET Runtime 2.0 Error Reporting .NET Runtime Application’
(-) HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cookies: “C:\Documents and Settings\Administrator\Cookies”
(+) HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cookies: “C:\Documents and Settings\LocalService\Cookies”
(+) HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache: “C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files”
(+) HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\History: “C:\Documents and Settings\LocalService\Local Settings\History”

———————————-
Files added:19
———————————-
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\home.lnk
C:\WINDOWS\system32\-54-16133
C:\WINDOWS\system32\799d.exe
C:\WINDOWS\system32\977o.dll
C:\WINDOWS\system32\9bee.dll
C:\WINDOWS\Tasks\ms.job
C:\WINDOWS\Temp\Cookies\index.dat
C:\WINDOWS\Temp\History\History.IE5\desktop.ini
C:\WINDOWS\Temp\History\History.IE5\index.dat
C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\0G7T6J1R\desktop.ini
C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\9IMAVVB8\desktop.ini
C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\desktop.ini
C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\G64GHMYZ\desktop.ini
C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\index.dat
C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\MRW01RXI\desktop.ini
C:\WINDOWS\Temp\tmp.exe
C:\WINDOWS\1b6u.bmp
C:\WINDOWS\91bd.exe
C:\WINDOWS\f91d.flv

———————————-
Folders added:12
———————————-
C:\Documents and Settings\Administrator\Local Settings\Temp\h8nil4o8
C:\Documents and Settings\All Users\Application Data\t
C:\Documents and Settings\All Users\Application Data\t\ad
C:\WINDOWS\Temp\Cookies
C:\WINDOWS\Temp\History
C:\WINDOWS\Temp\History\History.IE5
C:\WINDOWS\Temp\Temporary Internet Files
C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5
C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\0G7T6J1R
C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\9IMAVVB8
C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\G64GHMYZ
C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\MRW01RXI

———————————-
Total changes:104
———————————-

—————————————————————————————————————————-
Recommended software:
UnHackMe anti-rootkit and anti-malware
http://www.unhackme.com
RegRun Security Suite (Good choice for removal and protection)
http://www.regrun.com

1. Download UnHackMe free 30-day version

UnHackMe removes Adware/Spyware/Unwanted Programs/Browser Hijackers/Search Redirectors from your PC easily.

Free Download

UnHackMe is compatible with most antivirus software.
UnHackMe is 100% CLEAN, which means it does not contain any form of malware, including adware, spyware, viruses, trojans and backdoors. VirusTotal (0/56).
System Requirements: Windows 2000-Windows 8.1/10 32 or 64-bit. UnHackMe uses minimum of computer resources.

2. Double click on UnHackMe_setup.exe

You will see a confirmation screen with verified publisher: Greatis Software. Verified Publisher Greatis Software

Once UnHackMe has installed has installed the first Scan will start automatically

Review the detected threats

3. Carefully review the detected threats!

Click Remove button or False Positive.

What to do if you are unable to solve a problem?

UnHackMe Remote Assistant
  1. Open UnHackMe main screen.
  2. Click on a Remote Assistant button.
  3. Follow instructions on a screen.
  4. We will contact you and send a solution of your problem.
  5. Remote assistance is free during trial period.

Enjoy!

Dmitry Sokolov - author of UnHackMe