Folks
Over the past few weeks my PC has been repeatedly infected with a very nasty piece of malware, the purpose of which seems to be to redirect web searches to ad. sites, particularly for Groupon. It creates hidden dirs in the root dir. and reg. keys to run exes located in user/../temp dirs. Reinfections occur by crashing my browser (Firefox 3.6.17). If I remove the malware/keys I get reinfected again within a day or two.
I suspect that Silverlight is involved. Here is a dir /s listing of C:\Users\johnp\AppData\LocalLow\Microsoft\Silverlight
I know very little about Silverlight so would be grateful if someone more knowledgable can comment on whether its contents are 'kosher'
dir /s C:\Users\johnp\AppData\LocalLow\Microsoft\Silverlight
gives:-
31/05/2011 23:04 <DIR> is
11/07/2011 21:56 77 mssl.lck
Directory of C:\Users\johnp\AppData\LocalLow\Microsoft\Silverlight\is
31/05/2011 23:04 <DIR> utb2fraa.jah
Directory of C:\Users\johnp\AppData\LocalLow\Microsoft\Silverlight\is\utb2fraa.jah
31/05/2011 23:04 <DIR> zgznrtuj.qtb
Directory of C:\Users\johnp\AppData\LocalLow\Microsoft\Silverlight\is\utb2fraa.jah\zgznrtuj.qtb
31/05/2011 23:04 <DIR> 1
Directory of C:\Users\johnp\AppData\LocalLow\Microsoft\Silverlight\is\utb2fraa.jah\zgznrtuj.qtb\1
18/06/2011 12:03 <DIR> g
31/05/2011 23:04 <DIR> l
18/06/2011 12:03 <DIR> s
Directory of C:\Users\johnp\AppData\LocalLow\Microsoft\Silverlight\is\utb2fraa.jah\zgznrtuj.qtb\1\g
31/05/2011 23:04 <DIR> gcdjzxxajx2n1cbv4jurqx3yfvqbgmuprn5pq5wiiwc0vhfzmyaaagha
18/06/2011 12:03 <DIR> zyrvs3qsra0qmqdkjnogznvtdjoizt0kfep5hwwtoqo4itg5elaaaaba
Directory of C:\Users\johnp\AppData\LocalLow\Microsoft\Silverlight\is\utb2fraa.jah\zgznrtuj.qtb\1\g\gcdjzxxajx2n1cbv4jurqx3yfvqbgmuprn5pq5wiiwc0vhfzmyaaagha
31/05/2011 23:04 34 id.dat
31/05/2011 23:04 8 quota.dat
31/05/2011 23:04 8 used.dat
Directory of C:\Users\johnp\AppData\LocalLow\Microsoft\Silverlight\is\utb2fraa.jah\zgznrtuj.qtb\1
\g\zyrvs3qsra0qmqdkjnogznvtdjoizt0kfep5hwwtoqo4itg5elaaaaba
18/06/2011 12:03 18 id.dat
18/06/2011 12:03 8 quota.dat
18/06/2011 12:03 8 used.dat
Directory of C:\Users\johnp\AppData\LocalLow\Microsoft\Silverlight\is\utb2fraa.jah\zgznrtuj.qtb\1\l
File not found
Directory of C:\Users\johnp\AppData\LocalLow\Microsoft\Silverlight\is\utb2fraa.jah\zgznrtuj.qtb\1\s
31/05/2011 23:04 <DIR> gcdjzxxajx2n1cbv4jurqx3yfvqbgmuprn5pq5wiiwc0vhfzmyaaagha
18/06/2011 12:03 <DIR> pkbdxfnitekap1o0ei3wfxgq5twsk5xgoqkxhmx3bj4gdqbtpdaaacca
Directory of C:\Users\johnp\AppData\LocalLow\Microsoft\Silverlight\is\utb2fraa.jah\zgznrtuj.qtb\1
\s\gcdjzxxajx2n1cbv4jurqx3yfvqbgmuprn5pq5wiiwc0vhfzmyaaagha
31/05/2011 23:04 <DIR> f
31/05/2011 23:04 56 group.dat
31/05/2011 23:04 34 id.dat
Directory of C:\Users\johnp\AppData\LocalLow\Microsoft\Silverlight\is\utb2fraa.jah\zgznrtuj.qtb\1
\s\gcdjzxxajx2n1cbv4jurqx3yfvqbgmuprn5pq5wiiwc0vhfzmyaaagha\f
31/05/2011 23:05 2,989 __LocalSettings
Directory of C:\Users\johnp\AppData\LocalLow\Microsoft\Silverlight\is\utb2fraa.jah\zgznrtuj.qtb\1
\s\pkbdxfnitekap1o0ei3wfxgq5twsk5xgoqkxhmx3bj4gdqbtpdaaacca
18/06/2011 12:06 <DIR> f
21/06/2011 15:56 56 group.dat
18/06/2011 12:03 64 id.dat
Directory of C:\Users\johnp\AppData\LocalLow\Microsoft\Silverlight\is\utb2fraa.jah\zgznrtuj.qtb\1
\s\pkbdxfnitekap1o0ei3wfxgq5twsk5xgoqkxhmx3bj4gdqbtpdaaacca\f
18/06/2011 15:48 154 __LocalSettings
Regards
John
Over the past few weeks my PC has been repeatedly infected with a very nasty piece of malware, the purpose of which seems to be to redirect web searches to ad. sites, particularly for Groupon. It creates hidden dirs in the root dir. and reg. keys to run exes located in user/../temp dirs. Reinfections occur by crashing my browser (Firefox 3.6.17). If I remove the malware/keys I get reinfected again within a day or two.
I suspect that Silverlight is involved. Here is a dir /s listing of C:\Users\johnp\AppData\LocalLow\Microsoft\Silverlight
I know very little about Silverlight so would be grateful if someone more knowledgable can comment on whether its contents are 'kosher'
dir /s C:\Users\johnp\AppData\LocalLow\Microsoft\Silverlight
gives:-
31/05/2011 23:04 <DIR> is
11/07/2011 21:56 77 mssl.lck
Directory of C:\Users\johnp\AppData\LocalLow\Microsoft\Silverlight\is
31/05/2011 23:04 <DIR> utb2fraa.jah
Directory of C:\Users\johnp\AppData\LocalLow\Microsoft\Silverlight\is\utb2fraa.jah
31/05/2011 23:04 <DIR> zgznrtuj.qtb
Directory of C:\Users\johnp\AppData\LocalLow\Microsoft\Silverlight\is\utb2fraa.jah\zgznrtuj.qtb
31/05/2011 23:04 <DIR> 1
Directory of C:\Users\johnp\AppData\LocalLow\Microsoft\Silverlight\is\utb2fraa.jah\zgznrtuj.qtb\1
18/06/2011 12:03 <DIR> g
31/05/2011 23:04 <DIR> l
18/06/2011 12:03 <DIR> s
Directory of C:\Users\johnp\AppData\LocalLow\Microsoft\Silverlight\is\utb2fraa.jah\zgznrtuj.qtb\1\g
31/05/2011 23:04 <DIR> gcdjzxxajx2n1cbv4jurqx3yfvqbgmuprn5pq5wiiwc0vhfzmyaaagha
18/06/2011 12:03 <DIR> zyrvs3qsra0qmqdkjnogznvtdjoizt0kfep5hwwtoqo4itg5elaaaaba
Directory of C:\Users\johnp\AppData\LocalLow\Microsoft\Silverlight\is\utb2fraa.jah\zgznrtuj.qtb\1\g\gcdjzxxajx2n1cbv4jurqx3yfvqbgmuprn5pq5wiiwc0vhfzmyaaagha
31/05/2011 23:04 34 id.dat
31/05/2011 23:04 8 quota.dat
31/05/2011 23:04 8 used.dat
Directory of C:\Users\johnp\AppData\LocalLow\Microsoft\Silverlight\is\utb2fraa.jah\zgznrtuj.qtb\1
\g\zyrvs3qsra0qmqdkjnogznvtdjoizt0kfep5hwwtoqo4itg5elaaaaba
18/06/2011 12:03 18 id.dat
18/06/2011 12:03 8 quota.dat
18/06/2011 12:03 8 used.dat
Directory of C:\Users\johnp\AppData\LocalLow\Microsoft\Silverlight\is\utb2fraa.jah\zgznrtuj.qtb\1\l
File not found
Directory of C:\Users\johnp\AppData\LocalLow\Microsoft\Silverlight\is\utb2fraa.jah\zgznrtuj.qtb\1\s
31/05/2011 23:04 <DIR> gcdjzxxajx2n1cbv4jurqx3yfvqbgmuprn5pq5wiiwc0vhfzmyaaagha
18/06/2011 12:03 <DIR> pkbdxfnitekap1o0ei3wfxgq5twsk5xgoqkxhmx3bj4gdqbtpdaaacca
Directory of C:\Users\johnp\AppData\LocalLow\Microsoft\Silverlight\is\utb2fraa.jah\zgznrtuj.qtb\1
\s\gcdjzxxajx2n1cbv4jurqx3yfvqbgmuprn5pq5wiiwc0vhfzmyaaagha
31/05/2011 23:04 <DIR> f
31/05/2011 23:04 56 group.dat
31/05/2011 23:04 34 id.dat
Directory of C:\Users\johnp\AppData\LocalLow\Microsoft\Silverlight\is\utb2fraa.jah\zgznrtuj.qtb\1
\s\gcdjzxxajx2n1cbv4jurqx3yfvqbgmuprn5pq5wiiwc0vhfzmyaaagha\f
31/05/2011 23:05 2,989 __LocalSettings
Directory of C:\Users\johnp\AppData\LocalLow\Microsoft\Silverlight\is\utb2fraa.jah\zgznrtuj.qtb\1
\s\pkbdxfnitekap1o0ei3wfxgq5twsk5xgoqkxhmx3bj4gdqbtpdaaacca
18/06/2011 12:06 <DIR> f
21/06/2011 15:56 56 group.dat
18/06/2011 12:03 64 id.dat
Directory of C:\Users\johnp\AppData\LocalLow\Microsoft\Silverlight\is\utb2fraa.jah\zgznrtuj.qtb\1
\s\pkbdxfnitekap1o0ei3wfxgq5twsk5xgoqkxhmx3bj4gdqbtpdaaacca\f
18/06/2011 15:48 154 __LocalSettings
Regards
John