Hello everyone!
I’ve got a huge pile of malware from a false Adobe flash installer (FP_AX_CAB_INSTALLER.exe, according to my task manager) and it keep popping up, trying to install its own stuff
In addition, I’ve got the same problem as a lot of people here, I’ve got regular pop-up of these malwares…
Objects : C:\Windows\Installer.…\00000004.@ , 80000000.@ , 000000cb.@, 80000064.@
Infection : Win32:MalwareGen
Process C:\Windows\System32\services.exe
Objects C:\Windows\Installer.…\80000032.@
Infection : Win32:Downloader-PKU [TRJ]
Process C:\Windows\System32\services.exe
Here are the logs i’ve received :
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org
Database version: v2012.08.03.08
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Kevin :: KEVIN-VAIO [administrator]
03/08/2012 21:51:30
mbam-log-2012-08-03 (21-51-30).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 225534
Time elapsed: 6 minute(s), 47 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 1
C:\Users\Kevin\AppData\Roaming\bcrosr.dll (Trojan.Midhos) → Delete on reboot.
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|bcrosr (Trojan.Midhos) → Data: rundll32.exe “C:\Users\Kevin\AppData\Roaming\bcrosr.dll”,HrCopyLockBytesToStream → Quarantined and deleted successfully.
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 5
C:\Users\Kevin\AppData\Roaming\bcrosr.dll (Trojan.Midhos) → Delete on reboot.
C:\Users\Kevin\Desktop\age2_x1.exe (Trojan.FakeMS) → Quarantined and deleted successfully.
C:\Users\Kevin\AppData\Local\Temp\Temp1_rpc412.zip\rpc412_setup.exe (PAssword.Tool) → Quarantined and deleted successfully.
C:\Windows\Installer{6651dca3-d565-f92b-d551-89528331218a}\U\00000008.@ (Trojan.Dropper.BCMiner) → Quarantined and deleted successfully.
C:\Users\Kevin\Local Settings\TempDIR\BetterInstaller.exe (PUP.BundleInstaller.Somoto) → Quarantined and deleted successfully.
(end)