Backdoor.Prorat

Discussion in 'Malware Help (A Specialist Will Reply)' started by Gaaraqwet, Feb 25, 2009.

  1. Gaaraqwet

    Gaaraqwet Private E-2

    Ended up with a virus from somewhere, called Backdoor.prorat, I've run everything that the virus removal guide suggested, and it persists this is what I've done:

    1). Run Malwarebytes Anti-malware, removed it, relogged and it came back.

    2). Ran Malwarebytes Anti-Malware in safe mode, nothing found, relogged, came back.

    3). Turned off system restore, ran Mbam in normal mode, removed it, relogged, it came back.

    4). Ran Superantispyware in normal mode, removed it, it came back.

    5). Ran Superantispyware removed it, and it came back.

    6. Turned off system restore, returned hdd to factory settings, it was removed, and came back a week or so later..

    7). Repeated steps 1-5, removed it and it came back.

    8). Currently running Spybot and MGTools and ComboFix..



    It's very persistent, it comes in 2 .tmp files in my Local Settings/Temp folder, and they change their name every time I remove them. I've tried removal instructions from over a dozen sites and nothing..

    This is a laptop, so no Darik's Boot and Nuke.

    Attaching some things.

    Please help.
     
  2. Gaaraqwet

    Gaaraqwet Private E-2

    MBAM log
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No point in running MBAM if you don't fix it:
     
  4. Gaaraqwet

    Gaaraqwet Private E-2

    It needed me to restart to remove it, so it says that.

    Also heres my Superantispyware log..
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We want to see the log after the restart that shows it is removed. Now continue on with the other scans and attach them to your next post. Often just doing the scans will remove most of the malware, and then we can do the little cleanup that is necessary.
     
  6. Gaaraqwet

    Gaaraqwet Private E-2

    There is no other logs, theres just the one that mbam generates and the one that antispyware generates, and I've ran most of them and its still there.
     
  7. Gaaraqwet

    Gaaraqwet Private E-2

    Here's my MGtools.zip
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Why is there no anti-virus software or firewall installed on this system?

    That file is not showing in your logs....but that could be that every time SAS or MBAM removes it, it comes back since you have no AV program.

    You installed COmbofix....why am I not seeing a log from it?

    You need to empty:
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Download and install:
    Java Runtime 6
     
  9. Gaaraqwet

    Gaaraqwet Private E-2

    Really? I have avast professional, and I disabled my firewall because it's annoying. I installed combofix but it didn't give any log.

    I cleaned my temp folders and all except the virused item was deleted (virus won't go away cause its in use)



    I also learned it's crashing my msn messenger on startup =/
     
    Last edited: Feb 27, 2009
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not according to your logs. There is no antivirus installed.

    Would you rather be a little annoyed or alot annoyed when malware crashes your whole PC or worse....steals personal information.


    What happens when you run Combofix? Have you tried running it in safe mode?

    Again, give me the exact path of the items that you cant remove.
     
    Last edited by a moderator: Mar 1, 2009

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds