Restore from Hard Drive??

Discussion in 'Malware Help (A Specialist Will Reply)' started by Earnest1963, Feb 24, 2008.

  1. Earnest1963

    Earnest1963 Private E-2

    I got hacked by some malware that got on on my computer when I looked at a video on a news site Saturday AM. I loaded a Video Codec -- now I know I shouldn't have. McAfee Antivirus didn't detect it.

    I discovered the infection almost immediately and installed and ran Spyware Doctor.

    I found and removed several tainted files and Zlob downloader. I appeared to be able to clean these out, but Zlob downloader kept coming back immediately (and being found by the various Spyware detectors).

    I found your site and read the "read me" file. I ran the basic procedures (not the procedures for the Zlob Trojan) and also uninstalled IE 7. ( I normally run Netscape.)

    After several hours (~4), it appeared that the basic procedures had worked. No more spyware reports despite several runs thru the various spyware scanners.

    I cautiously began returning to work, to include reinstalling IE 7. Shortly after I did that I got a repeat of the original Zlob infection, plus load music thru the speakers. Internet access appeared to be spiking due heavy transmissions out and in, so I immediately locked down the firewall.

    After some consideration, determined that I just needed to reload the system. I called Gateway Support and they talked me thru a reload of the system from a protected sector on the hard drive. It takes the system back to the original "shipped with" software.

    The question is -- Is that good enough or do I need to go back to the original disks?

    So far, no additional spyware reports despite repeated scans.

    Thanks for your help.

    Earnest

    PS: The infected files were ekgvsnw.dll; bxlrvps.dll; bxlrvps.dll_old; alofkmn.dll ) I also found fkxvkns.exe just before reloading the software, but didn't shred it.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. Earnest1963

    Earnest1963 Private E-2

    Thanks for the reply.

    A couple of other questions:

    1. There was some sensitive information on the hard drive. I have assumed that information was compromised and have taken protective action -- changing passwords, accounts, etc. What is the chance that the information was compromised? How paranoid should I be?

    2. I ran the standard set of tools from the Read Me plus the Smitfraudfix check (not the fix). Combofix log, MGlogs.zip and Rapport (from Smitfraudfix) are attached. I noticed that rapport says that the 'hosts' file is corrupted. I looked at the file with spybot and cannot see anything wrong -- but I would know if anything is either missing or added, just that the file seems readable. Do I need to do anything about this?

    Thanks in advance for your help.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is hard to say as to how compromised your system was ...though taking pro-active steps is always a good idea if in doubt.

    Having Teatimer running can mess up the scans ...and you should have SpyBot re-immunize the host files.

    Otherwise you look good...If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  5. Earnest1963

    Earnest1963 Private E-2

    Unfortunately, I reinfected myself with a USB drive (now crushed).

    Reloaded the hard drive from it's protected partition (as before) and reinstalled the antivirus and antispyware programs. I've run McAfee, Spyware Doctor, Spybot-SD, and SuperAntiSpyware multiple times without finding any malware.

    Do I need to rerun Combofix and MGtools to make sure I'm clean now?

    How do I check & clean a USB drive without allowing it to reinfect my machine?

    Thanks for your help.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    About the only thing you can do is to scan items before you load it to a memory stick and allow it to be scanned with your regular scanning .

    I doubt you need to re-run the tools if you found the source of the infection and reloaded from the protected partition.
     
  7. Earnest1963

    Earnest1963 Private E-2

    Thanks very much for all of your help. I really appreciate your assistance.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem..safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds