09-27-2009 06:42 PM
here we go... i have been dealing with this for a week now.
norton finds nothing now. but found a virus called TROJAN HORSE and cleaned it on the 20th.
Malwarebytes finds the following:
Malwarebytes' Anti-Malware 1.41
Database version: 2861
Windows 5.1.2600 Service Pack 3
9/27/2009 3:36:53 PM
mbam-log-2009-09-27 (15-36-53).txt
Scan type: Full Scan (C:\|D:\|K:\|)
Objects scanned: 346225
Time elapsed: 3 hour(s), 18 minute(s), 47 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 0
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 7
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\system32\calc.dll (Backdoor.Bot) -> Delete on reboot.
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\calc.dll (Backdoor.Bot) -> Delete on reboot.
C:\Documents and Settings\HP_Administrator.WALKERFAMILY\protect.dll (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Administrator.WALKERFAMILY\Start Menu\Programs\Startup\scandisk.dll (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService\protect.dll (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{D7BD54B8-C977-4903-8CE7-9415B
C:\Documents and Settings\HP_Administrator.WALKERFAMILY\Start Menu\Programs\Startup\scandisk.lnk (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Administrator.WALKERFAMILY\Local Settings\Temp\nsrbgxod.bak (Trojan.Agent) -> Delete on reboot.
Big issue is after I reboot. The are still there...
I can't even get to safemode to try running programs here.
I really need some help.
I get redirected when I try to click on links in sites. I am unable to log in into https:// sites.
Help please...
Stacey
Solved! Go to Solution.
09-27-2009 07:23 PM
Hi
1. What programs have you used?
2. What rogue software came in or tried to come in??
Quads
09-27-2009 07:40 PM - edited 09-27-2009 07:41 PM
Nothing that I know of... I was working the Microsoft on the issue of after updating to the latest upgrade to IE8 and additional adds from them. After the update I unable to get to https:// sites. Anything with a password word would just reset the page. If I selected a link it would redirect with thefeedonline.com and a search engine. I know it's strange. But that is what happen... Any ideas on how to fix it?
Stacey
09-27-2009 07:51 PM
Hi
Download GMER and do a scan, then create a log, just to check if there is a background Rootkit
Quads
09-27-2009 08:25 PM
thanks for responding...
running now...
it may take a while...
i will reply with attachment.
stacey
09-28-2009 05:33 AM
System crash.
I will post later today if I can.
Stacey
09-28-2009 07:19 AM - edited 09-28-2009 07:21 AM
I found these 2 pages on a couple of the items you have.
calc.dll (Malicious Software)
http://info.prevx.com/aboutprogramtext.asp?PX5=FEF
protect.dll (Rootkit)
http://www.prevx.com/filenames/16023302822361271-X
09-28-2009 11:06 AM
Hi Stacey
Try a scan where just on the upper right hand side the "Services" and "Registry" are selected
Quads
09-28-2009 11:20 AM
Boofo
I know what they are, It's a matter of if anything else is in behind them so that is all in a combination or if that is all. sometimes the grouping even comes with Virut.
Quads
09-28-2009 12:17 PM
