![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
I have downloaded an infected file accidentally and been infected with the BackDoor.Generic15.XCE trojan. I doubled clicked the infected file to find that it promptly disappeared and then recieved an AVG security alert. AVG cannot remove it as it is "inaccessible".
I have a Windows install disk and am running 64-bit Windows 7 Home. The logs are attached as requested. |
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
Can you attach the MGlogs.zip as a result of running MGTools.exe please?
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#3
|
|||
|
|||
|
Here you go.
|
|
#4
|
||||
|
||||
|
I want you to run TDSSKiller so refer to the below for how to do so.
TDSSkiller - How to run Please also download MBRCheck to your desktop
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#5
|
|||
|
|||
|
Done and done. Logs attached.
|
| Sponsored links |
|
|
|
#6
|
||||
|
||||
|
Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode
Please disable Spybot's TeaTimer. How to disable Spybot's TeaTimer Uninstall the following softwares:
Now we need to use ComboFix by sUBs
Code:
KILLALL:: DirLook:: c:\programdata\CCP c:\program files (x86)\CCP c:\users\Josh\AppData\Local\CCP File:: C:\Windows\131794
Note: Do not mouseclick combofix's window while it is running. That may cause it to stall. If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected. Reboot your machine and install the most current and up to date version of Java available here at the below link: Java Runtime 6 Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this. Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#7
|
|||
|
|||
|
Done as instructed. Nothing really seemed off in the first place so I couldn't tell you anything different about the system now and at the start.
MGLogs are attached. The combofix one is too large, how should I send it to you? |
|
#8
|
|||
|
|||
|
Don't worry, I've stuck it in a zip folder.
|
|
#9
|
||||
|
||||
|
Quote:
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#10
|
|||
|
|||
|
The location is C:\Users\Josh\AppData\Local\Temp\svchost.exe (5968):\memory_00400000. Not sure about file name.
|
| Sponsored links |
|
|
|
#11
|
|||
|
|||
|
Could you please let me know how close you think we are to solving this problem? Thanks.
|
|
#12
|
||||
|
||||
|
Quote:
Quote:
Now we need to use ComboFix by sUBs
Code:
KILLALL:: File:: C:\Users\Josh\AppData\Local\Temp\svchost.exe
Note: Do not mouseclick combofix's window while it is running. That may cause it to stall. If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected. Let me know if avg is still complaining.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#13
|
|||
|
|||
|
Log attached. AVG picked up nothing in a scan I just did.
|
|
#14
|
||||
|
||||
|
Combofix ran in reduced functionality mode as you will see from viewing the log file. As long as avg has stopped complaining then it is not a problem. Let a day go by and let me know how things are running. If all is well, I will post the final steps for you to follow.
![]()
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#15
|
|||
|
|||
|
All running fine. Is the trojan gone?
|
| Sponsored links |
|
|
|
#16
|
|||
|
|||
|
Now that I have been using it a little bit, the system seems quite slow. I looked on Task Manager and it says that the memory usage is 914MB out of 2GB (not sure if this is normal). This is when no programmes are running.
I also had an AVG alert pop up with the name of the infected file and then asked me to move it to the Virus Vault. I did this, then deleted it form the Vault. Is there anything else I can do to make sure this trojan is gone? |
|
#17
|
||||
|
||||
|
Run a FULL system scan with avg and let me know the results.
Download OTL to your desktop.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL. Attach both of these logs into your next reply.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#18
|
|||
|
|||
|
AVG came up fine. Extras didn't appear but the other log did.
|
|
#19
|
||||
|
||||
|
If you are not having any other malware problems, it is time to do our final steps:
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Support Needed for Removal of Backdoor.IRCBot | Tomination | Malware Removal | 6 | 10-13-10 14:07 |
| PHP Script Needed Desperately | LadyYepperz | Programming | 1 | 12-14-08 16:12 |
| Consumer Advice desperately needed. . . | dangerous_dave | Hardware | 0 | 11-13-08 04:16 |
| Removal of Backdoor:Bandock or Backdoor:Bandook | rsgarfinkel | Malware Removal | 5 | 12-05-07 13:01 |
| windows help desperately needed!!! | nikki_d | Software | 8 | 03-06-06 10:03 |