dslreports logo
 
    All Forums Hot Topics Gallery
spc
uniqs
10

LoPhatPhuud
MVM
join:2002-01-06
Albuquerque, NM

1 recommendation

LoPhatPhuud to JimB

MVM

to JimB

Re: [Trojan] Trojan detected, may be clean now, just making sure

It appears that MBAM has fremoved the trojan. It's a zero access trojan attempting to make your computer part of a botnet.

There is some cleanup to do, and I want to check for other rootkits.

First:
Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, copy and paste the contents of the following box:


:OTL

:Services

:Reg

:Files
C:\WINDOWS\Installer\{3b66d4cd-a74f-bcda-4310-36f910d3c6ff}\

:Commands
[purity]
[emptytemp]
[EMPTYFLASH]
[Reboot]


[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Once you see a message box "Fix complete! Click OK to open the fix log."
[*]Click the OK button
[*]The log will open in Notepad (your default text editor).
{*]Save the log. Post a copy of that log in your next reply.


Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process.

If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start-All Programs-Accessories-Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTL\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Second:
Download and run Sophos AntiRootkit. Post the log in this thread, even if nothing is found.

You find link(s) and instructions here:
»Security Cleanup FAQ »Rootkit Detection Applications

JimB
@charter.com

JimB

Anon

Thanks so much! Here are the two logs. Since the Sophos scan didn't come up with any removable files, I only ran it once.

All processes killed
========== OTL ==========
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
C:\WINDOWS\Installer\{3b66d4cd-a74f-bcda-4310-36f910d3c6ff}\U folder moved successfully.
C:\WINDOWS\Installer\{3b66d4cd-a74f-bcda-4310-36f910d3c6ff}\L folder moved successfully.
C:\WINDOWS\Installer\{3b66d4cd-a74f-bcda-4310-36f910d3c6ff} folder moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 4420 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 50469013 bytes
->Flash cache emptied: 492 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 48.00 mb

[EMPTYFLASH]

User: Administrator
->Flash cache emptied: 0 bytes

User: All Users

User: Default User

User: LocalService

User: NetworkService

Total Flash Files Cleaned = 0.00 mb

OTL by OldTimer - Version 3.2.53.1 log created on 07102012_125720

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
_________________

Sophos Anti-Rootkit Version 1.5.20 (c) 2009 Sophos Plc
Started logging on 7/10/2012 at 13:04:01 PM
User "Administrator" on computer "LIFEBOOK"
Windows version 5.1 SP 3.0 Service Pack 3 build 2600 SM=0x100 PT=0x1 Win32
Info: Starting process scan.
Info: Starting registry scan.
Info: Starting disk scan of C: (NTFS).
Hidden: file C:\WINDOWS\I386\REGEDIT.EXE
Hidden: file C:\Documents and Settings\Administrator\My Documents\Downloads\Firefox Setup 7.0.1.exe
Hidden: file C:\Documents and Settings\Administrator\My Documents\Downloads\Firefox Setup 9.0.1.exe
Stopped logging on 7/10/2012 at 13:25:36 PM