On Friday I downloaded a file that a customer of mine wanted to show me for a colour refernece. I right clicked and did a scan with my virus scanner (f-secure through shaw cable). It said it was fine so I double clicked on the file.
A warning came up from the virus program that said the computer was infected with a trojan. I don't know the name. It recommended innoculating, but couldn't so it renamed. Right after that another one came up saying the same thing, same procedure.
I then ran a complete scan of my computer and it didn't find anything. Everything was normal on Saturday, except when I came back to my computer after dinner there was another virus warning. I hadn't clicked on anything. I saw something about backdoor in the title.
I went through the same procedure as on Friday, virus program renamed the file. I've done a Hijack This log as requested. I have no idea what any of it means. Thanks for any help.
Dell Dimension 5150
Win XP
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:04:32 PM, on 10/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
* If you are using any P2P (file sharing) programs, please remove them before we clean your computer.
The nature of such software and the high incidence of malware in files downloaded with them is counter productive to restoring your PC to a healthy state.
* If this computer belongs to someone else, do you have authority to apply the fixes we will use?
* Have you already fixed entries using HijackThis? If so, please restore all the backups and then post another log.
* After we begin working, please print or copy all instructions to Notepad in order to assist you when carrying out procedures.
Please follow all instructions in sequence. Do not, on your own, install/re-install any programs or run any fixes or scanners that you have not been instructed to use because this may cause conflicts with the tools that I am using.
** We may be using some specialized tools during our fix. Certain embedded files that are part of legitimate programs or specialized fix tools such as process.exe, restart.exe, SmiUpdate.exe, reboot.exe, ws2fix.exe, prcviewer.exe and nircmd.exe may at times be detected by some anti-virus/anti-malware scanners as a "RiskTool", "Hacking tool", "Potentially unwanted tool", or even "malware (virus/trojan)" when that is not the case.
Such programs have legitimate uses in contexts where an authorized user or administrator has knowingly installed it. These detections do not necessarily mean the file is malware or a bad program. It means it has the potential for being misused by others. Anti-virus scanners cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert you or even automatically remove them.
* If your replies do not fit in one post while we are handling your issue, please reply to yourself until all text is submitted. It may take several posts.
I do not see any active malware in your log, however, without knowing the name of the file or which Backdoor Trojan was found, it is rather hard to know how much the system was compromised. If it turns up again, please write it down and let us know.
After your reply, we will run some additional diagnostics to see what lurks in there.
I don't have any cracked software nor do I use any P2P applications. There may be some that came installed with my computer, but I don't even know the names of most P2P software. Do I need to remove those even if I don't use them?
I can give you a link to the file that I think caused the problem. It's in my messages on a venue I sell at. Let me know if that will help.
Cracked software should not have come on your computer if you bought it new. Neither would P2P software.
** Please perform a scan with
Kaspersky Webscan Online Virus Scanner 1. Click the "
Kaspersky Online Scanner" button (
NOT "Kaspersky File Scanner" ).
2. Read the Requirements and Privacy statement, then select "
Accept".
3. A new window will appear promting you to install an ActiveX component from Kaspersky - "
Do you want to install this software?".
4. Click "
Yes" or select "
Install" to download the ActiveX controls that allows ActiveScan to run.
5. When the download is complete it will say ready, click "
Next".
6. Click "
Scan Settings" and check the option to use the
Extended Database if available otherwise Standard).
7. Click "
Scan Options" and select both "
Scan Archives" and "
Scan Mail Bases".
8. Click "
OK".
9. Under "
Select a target to scan", click on "
My Computer".
10. When the scan is complete choose to save the results as "
Save as Text" named kaspersky.txt to your desktop and post it in your next reply along with a fresh HijackThis log.
I'm in the process of doing the kaspersky scan. It's att 99%. So far it says there are 2 viruses. Also, just a couple of minutes ago my F-secure popped up and said it detected a virus called IM-worm.win32.agent.bl
It couldn't disinfect it, so it renamed it. Will this affect the scan that kaspersky is doing. I hope not because it's taken about 2 hours so far. Thanks.
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:05:23 PM, on 11/02/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16574) Boot mode: Normal
------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER REPORT Monday, February 11, 2008 12:03:16 PM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 11/02/2008 Kaspersky Anti-Virus database records: 557799 -------------------------------------------------------------------------------
Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true
Scan Target - My Computer: C:\ D:\ E:\
Scan Statistics: Total number of scanned objects: 104117 Number of viruses found: 2 Number of infected objects: 2 Number of suspicious objects: 0 Duration of the scan process: 01:59:53
Infected Object Name / Virus Name / Last Action C:\a.0at Infected: Trojan.BAT.KillFire.d skipped C:\Documents and Settings\All Users\Application Data\F-Secure\logs\FSMA\fsma.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3ad391678a806ec4d691e83aaa393b6f_24adf822-76f7-4481-b30b-ff1b40f8687f Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\logs\ehRecvr.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\ActivityLog\InboxLOG.txt Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\ActivityLog\OutboxLOG.txt Object is locked skipped C:\Documents and Settings\Gina\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\DSAgnt.log Object is locked skipped C:\Documents and Settings\Gina\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\DSAgnt_GTActions.log Object is locked skipped C:\Documents and Settings\Gina\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\gdql_d_DSAgnt.log Object is locked skipped C:\Documents and Settings\Gina\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\glog.log Object is locked skipped C:\Documents and Settings\Gina\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Gina\Local Settings\Application Data\ApplicationHistory\TransferAgent.exe.91f03f4d.ini.inuse Object is locked skipped C:\Documents and Settings\Gina\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Gina\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Gina\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Gina\Local Settings\Temp\~DFB9B8.tmp Object is locked skipped C:\Documents and Settings\Gina\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped C:\Documents and Settings\Gina\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Gina\ntuser.dat Object is locked skipped C:\Documents and Settings\Gina\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Program Files\Shaw Secure\Anti-Virus\dbupdate.log Object is locked skipped C:\Program Files\Shaw Secure\Anti-Virus\deleteme_msg.log Object is locked skipped C:\Program Files\Shaw Secure\Anti-Virus\fsqh.exe.Qrt.log Object is locked skipped C:\Program Files\Shaw Secure\Anti-Virus\perf.dat Object is locked skipped C:\Program Files\Shaw Secure\Anti-Virus\power.dat Object is locked skipped C:\Program Files\Shaw Secure\Common\policy.bpf Object is locked skipped C:\Program Files\Shaw Secure\Common\policy.ipf Object is locked skipped C:\Program Files\Shaw Secure\FSAUA\fsbwupst.log Object is locked skipped C:\Program Files\Shaw Secure\FSAUA\program\fsaua.dbg Object is locked skipped C:\Program Files\Shaw Secure\FSAUA\program\fsaua.log Object is locked skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP575\A0031857.0om Infected: IM-Worm.Win32.Agent.bl skipped C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP577\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\ModemLog_Conexant D850 56K V.9x DFVc Modem.txt Object is locked skipped C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{67317936-E5AD-40B7-A8C3-616271EC87D3}.crmlog Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\EventCache\{2DB36143-7257-40A5-B099-B5FD66424D12}.bin Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\DEFAULT Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SYSTEM Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\Temp\AVP66AF.tmp Object is locked skipped C:\WINDOWS\Temp\AVP66B0.tmp Object is locked skipped C:\WINDOWS\Temp\AVP66B5.tmp Object is locked skipped C:\WINDOWS\Temp\AVP66B6.tmp Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped C:\WINDOWS\wkssvc.exe Object is locked skipped
KAV and F-Secure may have bumped into each other. One of those infections that KAV found was in an F-Secure update from August, so if you are staying current with your updates, F-Secure probably already took care of it. The one that caused an alert is in your System Restore. That may have been when KAV was scanning that. We'll take care of that later. Let's run Dr. Web. After you download it, please go offline to run the scan. *We'll do it in Safemode. Please make sure F-Secure is disabled during the scan.
Please download
DrWeb-CureIt & save it to your desktop.
DO NOT perform a scan yet.
Reboot your computer in SAFE MODE using the
F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".
Scan with DrWeb-CureIt as follows:
Double-click on cureit.exe to start the program. An "Express Scan of your PC" notice will appear.
Under "Start the Express Scan Now", Click "OK" to start. This is a short scan that will scan the files currently running in memory and when something is found, click the Yes button when it asks you if you want to cure it.
Once the short scan has finished, Click Options > Change settings
Choose the "Scan tab" and UNcheck "Heuristic analysis"
Back at the main window, click "Select drives" (a red dot will show which drives have been chosen)
If not given a choice select "custom scan".
Then click the "Start/Stop Scanning" button (green arrow on the right) and the scan will start.
When done, a message will be displayed at the bottom advising if any viruses were found.
Click "Yes to all" if it asks if you want to cure/move the file.
When the scan has finished, look if you can see the icon next to the files found. If so, click it, then click the next icon right below and select "Move incurable".
( This will move it to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if it can't be cured)
Next, in the Dr.Web CureIt menu on top, click file and choose save report list.
Save the DrWeb.csv report to your desktop.
Exit Dr.Web Cureit when done.
Important!Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)
Before I proceed, I would like to ask some questions.
Can you tell how long the virus has been in my computer? Shoud I be worrried that by doing online banking, I've been compromised. I'm not even sure how I got this virus. I don't open any email attachments nor do I do any P2P activities. The only thing I can think of, and this is when the first warning popped up, was when my customer gave me a link to download of a picture. I do remember the name of the file as having msn in the title. The link is still in my online messages in the venue I sell in if that would help in identifying it...maybe it doesn't matter. Knowing how I acquired it would help me though.
I've been wanting to restore my computer back to factory default with PC recovey that comes with Dell computers. Maybe now would be a good time to do it rather than trying to clean out the malware??
If I do go the route of restoring, can I go ahead and do backups of data files, or is it a possiblility that some files could be infected?
Lastly, can I log into my online shop, email, etc safely before I do the restore or cleanup, or is that too risky? I hope I haven't asked too many questions. I really appreciate your time and effort in helping me. Thanks.
No, I cannot tell how long the malware was on your computer. We can download and run a program that will give us a report within 30 days.
If you are referring to the IM-Worm.Win32.Agent.bl in your System Restore, a Worm can spread across computer networks via security holes on vulnerable machines connected to the network. Worms can also spread through email by sending copies of itself to everyone in the user's address book.
The decision to do a factory restore is up to you. If those are the only two problems, neither one of them is active anymore.
I think it's safe to back up your documents. I wish you had written down the information about that trojan so I could be 100% sure, but from the information I have to go on, I think your online shopping is safe.
If you have access to F-Secure quarantine, can you look in there and see the filename?
Bugbatter
4 Apprentice
•
20487 Posts
1019
0
Posted February 11th, 2008 12:00
Welcome. Thank you for using Dell Community Forums.
I am reviewing your log.
In the meantime, you can help me by doing the following:
* Have you have posted this issue on another forum? If so, please provide a link to the topic.
* If you are using any cracked software, please remove it.
Definition of cracked software:
http://en.wikipedia.org/wiki/Software_cracking
* If you are using any P2P (file sharing) programs, please remove them before we clean your computer.
The nature of such software and the high incidence of malware in files downloaded with them is counter productive to restoring your PC to a healthy state.
* If this computer belongs to someone else, do you have authority to apply the fixes we will use?
* Have you already fixed entries using HijackThis? If so, please restore all the backups and then post another log.
* After we begin working, please print or copy all instructions to Notepad in order to assist you when carrying out procedures.
Please follow all instructions in sequence. Do not, on your own, install/re-install any programs or run any fixes or scanners that you have not been instructed to use because this may cause conflicts with the tools that I am using.
** We may be using some specialized tools during our fix. Certain embedded files that are part of legitimate programs or specialized fix tools such as process.exe, restart.exe, SmiUpdate.exe, reboot.exe, ws2fix.exe, prcviewer.exe and nircmd.exe may at times be detected by some anti-virus/anti-malware scanners as a "RiskTool", "Hacking tool", "Potentially unwanted tool", or even "malware (virus/trojan)" when that is not the case.
Such programs have legitimate uses in contexts where an authorized user or administrator has knowingly installed it. These detections do not necessarily mean the file is malware or a bad program. It means it has the potential for being misused by others. Anti-virus scanners cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert you or even automatically remove them.
* If your replies do not fit in one post while we are handling your issue, please reply to yourself until all text is submitted. It may take several posts.
I do not see any active malware in your log, however, without knowing the name of the file or which Backdoor Trojan was found, it is rather hard to know how much the system was compromised. If it turns up again, please write it down and let us know.
After your reply, we will run some additional diagnostics to see what lurks in there.