Has my computer been infected, need help.

Discussion in 'Malware Help (A Specialist Will Reply)' started by ricky22, Mar 5, 2010.

  1. ricky22

    ricky22 Private E-2

    Hi, I've been away and allowed two people to use my computer, one of them downloaded and installed a flv player from www.download.com. Since I've been back I sent the program to be scanned by VirusTotal, which came back with these infections for the file:

    W32/BackdoorX.DHLT
    Win32.Small.guj
    Backdoor/Small.gue

    I have checked and the first one seems very nasty and can spread to my usb drive, yes I did plug it in before I found the infected file, the program has been uninstalled and deleted and I have been googling away but still do not know if I'm infected or what other things may have been downloaded, can anyone help me check my computer for these infections, also the two people both deny downloding the program?, could my usb pen drive also be infected, I'm very worried, thanks for your time and help.

    I've followed all of the windows cleaning procedure and have the logs which I will try to attach.
     

    Attached Files:

  2. ricky22

    ricky22 Private E-2

    Please read my first thread below. Here are the MGlogs zip fie logs.
     

    Attached Files:

  3. ricky22

    ricky22 Private E-2

    Hi. just an update, I turned system restore off and did my scans in safe mode, I had to restart a few times to remove some secuity software that was effecting combofix. When I finished and restarted in normal mode system restore was on, will I have to run the scans again, thanks
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks!

    Please follow only the requested steps in our READ & RUN ME First guide, and instructions given to you. * Having an infected restore point is better that not having any at all should something go wrong in the malware removal process.

    I am currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Our queue is working the oldest threads first.

    Thanks for your patience.
    dr.m
     
  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, ricky22

    I strongly recommend that you clean up this account's Desktop immediately leaving only links. [ C:\Documents and Settings\Ricky\desktop] Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least - it can have an effect on your PCs performance.

    I find no malware present in your logs; however your SUPERAntiSpyware version is outdated.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new "Quick scan" of your system. And attach this new log.

    Comment: You have quite a mess in your "C:\Documents and Settings\Ricky\My Documents" directory!
    e.g.
    Do you know what this is? C:\WINDOWS\is-JBBK3.exe

    Using Windows Explorer - navigate to and delete:
    Delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Now go to this link MGTools and download the new version of MGtools.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • C:\MGlogs.zip
    • updated SASlog.txt log from SuperAntiSpyware.

    dr.m
     
  6. ricky22

    ricky22 Private E-2

    Hi, thanks for all of your help, it looks like I did things wrong, I started again as msconfig did not stay in Normal mode as I must have not applied before quiting, Spybot - Search & Destroy had one thing in IE Tweaks still ticked, the lock host files, and RootRepeal did not scan all my dives.

    I've done it all again but before reading your reply about SUPERAntiSpyware being out of date, would I have to start over or just up-date that program and re-scan. I will try and clean up my drive as you suggested, could you tell me one thing, if the program was installed and had those infections reported by VirusTotal would I not be infected. I did some googling before posting and read about the reported infections and how to remove them and deleted to registry entries said to be created by them, but could not find all the files that these infections created.

    I've attached the new scan results, I did these scans before reading your last reply, thanks again, will update SUPER and post when I've re-scanned. My D data partition is a mess and I'm finding all sorts on there as it's a shared computer.
     

    Attached Files:

  7. ricky22

    ricky22 Private E-2

    Can only find the JBBK3.EXEC: in C:\WINDOWS\Prefetch. Will re-download MGtools.exe to C: and re-scan.
     
  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, ricky22

    First - now that I'm working your thread, please only follow the instructions I post. Doing things on your own can complicate the removal process and make this a l-o-n-g drawn-out affair. ;)

    Answering your questions:
    1) Spybot locking your hosts file - is a good thing!
    2) RootRepeal can run randomly on different machines. While reviewing your logs, I'll see if we need to use another tool.
    3) After following my previous instructions on replacing your old SAS version - just update the newest version \ run a new "Quick Scan" \ attach that new log only.
    4) The effectiveness of your protection software may have prevented the malware from fully installing - therefore you might not find entries shown posted on the web. *Note - the names of infected files often "morph" or have random names; they may have different names per individual PC's.

    Please be patient and give me time to go through your present logs, but do attach the new SASlog.txt after installing, updating and running the newest version.

    dr.m
     
  9. ricky22

    ricky22 Private E-2

    Sorry for delay, have included scan results, no sign of JBBK3.EXE
     

    Attached Files:

  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :)

    I see no signs of infection, ricky.

    Your logs look good! If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double-click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work through the below link:

    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
  11. ricky22

    ricky22 Private E-2

    Hi, thanks for all of your help, when I turned my computer on this morning combofix and all the programs used had vanished, I re-downloaded combofix and run it again so that I could uninstall it but it didn't work, it rebooted this time by it's self to finish the scan. Computer is a bit messed up but I'll sort it, thanks again.
     
  12. ricky22

    ricky22 Private E-2

    Forgot to ask, do I reset msconfig to what it was, selective?
     
  13. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    *Unless you are diagnosing a problem, you should leave your startup mode in "Normal Startup Mode".

    dr.m
     
  14. ricky22

    ricky22 Private E-2

    Looks like my computer has been hacked after all, can't change any security options in IE8, When I click on Tools, then internet options, the foloowing Pops Up:

    Restrictions - This operation has been cancelled due to restriction in effect on this computer. Please contact the system administrator.

    Many other windows funtions do not work anymore as well, will have to delete all of my data and try cleaning my drive before re-installing windows, after reading this how can I be sure of anything?

    http://www.microsoft.com/technet/community/columns/secmgmt/sm0504.mspx
     
  15. ricky22

    ricky22 Private E-2

    Please don't think I was being ungrateful, you help was much appriciated, it was majorgeeks guide about turning my security and especially my firewall off to run scans that was a very bad idea with this type of infection, thanks again for your time.

    Hijacks and infections are now appearing each day, turning my protection off must of made it easier for the backdoor trojan.
     
  16. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    The only time you're instructed to do this is "Close or disable all running Antivirus, Antispyware, and Firewall programs as they may interfere with the proper running of ComboFix." And - if you would read any of our post reply instructions for the running of a "CFscript.txt", you will also find wording like:
    And - other than having you delete some temporary files, I stated:
    In fact, the only thing found in every scan log that you gave me was this being found and removed by ComboFix, in your FIRST attachments --->c:\windows\system32\AVSredirect.dll

    My "Best Wishes" in straightening out your other problems.
    dr.m
     
    Last edited: Mar 11, 2010

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds