Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Inactive Support Threads
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Support
Windows Malware Removal Help & Support
Unknown virus, possibly keylogger
Message
<blockquote data-quote="Fiery" data-source="post: 115915" data-attributes="member: 9"><p>Hello <img src="data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7" class="smilie smilie--sprite smilie--sprite109" alt=":)" title="Smile :)" loading="lazy" data-shortname=":)" /></p><p></p><p>Here is a good summary of what a backdoor infection is: http://www.geekstogo.com/190/what-is-a-backdoor-trojan/</p><p></p><p>Regarding the OTL fix, I don't think you copied the entire script. Please do so again.</p><p></p><p><span style="font-size: 15px"><strong>STEP 1</strong></span>:</p><p>Open OTL. Under <strong>custom scan/fixes</strong>, copy and paste the following:</p><p></p><ul> <li data-xf-list-type="ul"><br /> :OTL<br /> O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D98D3097-8A4D-4F1A-947B-C59AD700C145}: DhcpNameServer = 8.8.8.8<br /> [2011/08/14 19:01:33 | 000,000,256 | ---- | C] () -- C:\Users\FW56E\AppData\Roaming\090024D6292A4E<br /> [2010/04/30 01:46:49 | 000,005,009 | ---- | C] () -- C:\ProgramData\tbuxfygh.lbm<br /> @Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:8CEFE51A<br /> @Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:CE2C623F<br /> <br /> :Files<br /> ipconfig /flushdns /c<br /> <br /> :Commands<br /> [EMPTYTEMP]</li> </ul><p></p><p>Then click <strong>Run Fix</strong>. Let your PC reboot to normal mode. A new log will be created automatically, post the content in the next reply.</p><p></p><p><span style="font-size: 15px"><strong>STEP 2</strong></span></p><p>Next, we will use FRST to remove some drivers.</p><p></p><p>Open notepad and copy & paste the following:</p><p></p><p></p><p></p><p>and save it as <span style="color: #FF0000"><strong>fixlist.txt</strong></span> onto your flash drive.</p><p></p><p>Then, boot to system recovery, plug in your flash drive, open FRST and click <strong>fix</strong>. Post the generated log.</p><p></p><p><span style="font-size: 15px"><strong>STEP 3</strong></span></p><p>Please download<span style="color: #FF0000"> ComboFix</span> from one of these locations:</p><p></p><p><a title="External link" href="http://download.bleepingcomputer.com/sUBs/ComboFix.exe" rel="external"><<strong>>Link 1</<strong>></a></strong></strong></p><p><strong><strong><a title="External link" href="http://www.infospyware.net/antimalware/combofix/" rel="external"><<strong>>Link 2</<strong>></a></strong></strong></strong></strong></p><p><strong><strong><strong><strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><ul></strong></strong></strong></strong></p><p><strong><strong><strong><strong> <li>Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools</strong></strong></strong></strong></p><p><strong><strong><strong><strong>See <a title="External link" href="http://www.bleepingcomputer.com/forums/topic114351.html" rel="external">HERE</a> for help</li></strong></strong></strong></strong></p><p><strong><strong><strong><strong> <li>Double click on Combo-Fix & follow the prompts.</li></strong></strong></strong></strong></p><p><strong><strong><strong><strong> <li>As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's <strong>ly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.</li></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong> <li>Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.</li></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong></ul></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong>**Please note: (This applies to Windows XP systems only) If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.</strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><img src="http://img.photobucket.com/albums/v706/ried7/RcAuto1.gif" alt="Posted Image" /></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong>Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:</strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><img src="http://img.photobucket.com/albums/v706/ried7/whatnext.png" alt="Posted Image" /></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong>Click on <<strong>>Yes</<strong>>, to continue scanning for malware.</strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong>When finished, ComboFix will produce a log, please post it in your next reply</strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><<strong>>Note:</<strong>></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><span style="color: #FF0000">1. Do not mouseclick combofix's window while it's running. That may cause it to stall!</span></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><span style="color: #FF0000">2. Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.</span></strong></strong></strong></strong></strong></strong></strong></strong></strong></p></blockquote><p></p>
[QUOTE="Fiery, post: 115915, member: 9"] Hello :) Here is a good summary of what a backdoor infection is: http://www.geekstogo.com/190/what-is-a-backdoor-trojan/ Regarding the OTL fix, I don't think you copied the entire script. Please do so again. [SIZE=4][b]STEP 1[/b][/SIZE]: Open OTL. Under [b]custom scan/fixes[/b], copy and paste the following: [list] :OTL O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D98D3097-8A4D-4F1A-947B-C59AD700C145}: DhcpNameServer = 8.8.8.8 [2011/08/14 19:01:33 | 000,000,256 | ---- | C] () -- C:\Users\FW56E\AppData\Roaming\090024D6292A4E [2010/04/30 01:46:49 | 000,005,009 | ---- | C] () -- C:\ProgramData\tbuxfygh.lbm @Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:8CEFE51A @Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:CE2C623F :Files ipconfig /flushdns /c :Commands [EMPTYTEMP] [/list] Then click [b]Run Fix[/b]. Let your PC reboot to normal mode. A new log will be created automatically, post the content in the next reply. [SIZE=4][b]STEP 2[/b][/SIZE] Next, we will use FRST to remove some drivers. Open notepad and copy & paste the following: and save it as [color=#FF0000][b]fixlist.txt[/b][/color] onto your flash drive. Then, boot to system recovery, plug in your flash drive, open FRST and click [b]fix[/b]. Post the generated log. [SIZE=4][b]STEP 3[/b][/SIZE] Please download[color=#FF0000] ComboFix[/color] from one of these locations: <a title="External link" href="http://download.bleepingcomputer.com/sUBs/ComboFix.exe" rel="external"><[b]>Link 1</[b]></a> <a title="External link" href="http://www.infospyware.net/antimalware/combofix/" rel="external"><[b]>Link 2</[b]></a> <ul> <li>Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools See <a title="External link" href="http://www.bleepingcomputer.com/forums/topic114351.html" rel="external">HERE</a> for help</li> <li>Double click on Combo-Fix & follow the prompts.</li> <li>As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's [b]ly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.</li> <li>Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.</li> </ul> **Please note: (This applies to Windows XP systems only) If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures. <img src="http://img.photobucket.com/albums/v706/ried7/RcAuto1.gif" alt="Posted Image" /> Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message: <img src="http://img.photobucket.com/albums/v706/ried7/whatnext.png" alt="Posted Image" /> Click on <[b]>Yes</[b]>, to continue scanning for malware. When finished, ComboFix will produce a log, please post it in your next reply <[b]>Note:</[b]> [color=#FF0000]1. Do not mouseclick combofix's window while it's running. That may cause it to stall! 2. Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.[/color][/b][/b][/b][/b][/b][/b][/b][/b][/b] [/QUOTE]
Insert quotes…
Verification
Post reply
Top