Possible Bot or Keylogger

Discussion in 'Malware Help (A Specialist Will Reply)' started by jc2010, Oct 9, 2010.

  1. jc2010

    jc2010 Private E-2

    Hello,

    I received an email from my ISP indicating that one of my computers might be infected with a bot. Trying to get any more information from them was impossible, so I turned to the internet and found you all! Prior to finding this website, I ran Norton, Spybot, and some MS Windows Malware scanner (suggested by Comcast) and came up with nothing. I knew that didn't mean I had a clean bill of health, though...

    I'm typing this on my laptop so as to decrease the amount of time my desktop (the one I believe to have the issues) is online. I will reply to this post with my logs once I submit this. I have gone through and edited the logs and replaced my name with my initials where it appeared to abide by the forum rules.

    I think most things came up negative. There were some IB1.tmp - IB9.tmp files in my temp folder, and the ib1 - ib5 were flagged by Root Repeal.

    Thank you all for any help you can provide!

    John C.
     
  2. jc2010

    jc2010 Private E-2

    The first four logs are attached.
     

    Attached Files:

  3. jc2010

    jc2010 Private E-2

    MG Tools zip folder is attached. Thanks again!
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We can remove those temp files, but I am not seeing any malware in your logs.

    Please double-click the RootRepeal.exe previously downloaded.

    * Select File then Scan
    * On the Select Drives form select drive C by "ticking" the box for drive C and click OK
    * When the scan is complete - highlight each of the following file(s) (one at a time if more then one is listed) by left clicking it. Then use right mouse click and select the Wipe File option only for each file.
    C:\WINDOWS\Temp\ib5.tmp
    C:\WINDOWS\Temp\ib6.tmp
    C:\WINDOWS\Temp\ib7.tmp
    C:\WINDOWS\Temp\ib8.tmp
    C:\WINDOWS\Temp\ib9.tmp
    * After Wiping all files, immediately reboot your pc!

    Tell me what malware issues you are having, if any.
     
  5. jc2010

    jc2010 Private E-2

    Tim,

    I will go home and make those changes and report back later this evening.

    Thank you for your quick response.

    Enjoy the weekend, and take care!

    John C
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    IIRC those files were of 0 size. It might be a good idea once you are home to run an online scan:
    eSet Online Scan.
     
  7. jc2010

    jc2010 Private E-2

    Tim,

    Ran the online scan you suggested after I wiped the files. Only thing that came up was Win32/PrcView application, which (from digging around online a bit) looks like it was probably flagged as a potential issue and isn't something to worry about.

    Thanks again for your help today. I really appreciate it.

    All the best,

    John C.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  9. jc2010

    jc2010 Private E-2

    Followed all of your advice there. Looks like I'm good to go!

    Tim, thank you again for your prompt and friendly help. My best regards to you and this extremely helpful website!

    John C.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds