This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] "Your System Has Been Infected"

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Sorry about the delay but I was away for the weekend. Now let's proceed with the log:

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\Documents and Settings\Compaq Evo\Desktop\Programs\LimewireSetup.exe


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

NEXT


Please do the following:

  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:


C:\Program Files\HBLite\bin\11.0.181.0\HBLiteSAAX.dll

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.



Please do the same for the following files:

C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Internet Explorer\Desktop.htt

Thank you
Ok so I was able to run the scan on these files C:\Program Files\HBLite\bin\11.0.181.0\HBLiteSAAX.dll

They wouldn't allow me to copy and paste into the top box but I was able to find the file however I was unable to find the second set of files you wanted scanned. But here is the results for the first set

VirSCAN.org Scanned Report :
Scanned time : 2010/06/01 10:17:44 (PDT)
Scanner results: 17% Scanner(s) (6/36) found malware!
File Name : HBLiteSAAX.dll
File Size : 316720 byte
File Type : PE32 executable for MS Windows (DLL) (GUI) Intel 80386 32-bi
MD5 : 0f807ea01a7ae716e63cd16cfe73a00a
SHA1 : 0f95a65a29f143a7368f58047a022b5b156fae26
Online report : http://virscan.org/report/839ce386486c3ae6…2960c66ffa.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 5.0.0.11 20100601033116 2010-06-01 0.31 AdWare.AdSpy!IK
AhnLab V3 … .. – 1.11 -
AntiVir 8.2.1.242 7.10.7.209 2010-06-01 0.25 ADSPY/Hotbar.316720
Antiy 2.0.18 20100601.4601534 2010-06-01 0.12 -
Arcavir 2009 201006011032 2010-06-01 0.10 -
Authentium 5.1.1 201006011249 2010-06-01 2.01 -
AVAST! 4.7.4 100601-1 2010-06-01 0.02 -
AVG 8.5.793 271.1.1/2910 2010-06-01 0.27 -
BitDefender 7.90123.6116088 7.31962 2010-06-01 3.88 -
ClamAV 0.96.1 11111 2010-06-01 0.08 -
Comodo 3.13.579 4977 2010-06-01 0.84 UnclassifiedMalware
CP Secure 1.3.0.5 2010.06.01 2010-06-01 0.08 -
Dr.Web 5.0.2.3300 2010.06.01 2010-06-01 7.60 -
F-Prot 4.4.4.56 20100601 2010-06-01 2.21 -
F-Secure 7.02.73807 2010.06.01.04 2010-06-01 0.24 -
Fortinet 4.1.133 12.8 2010-06-01 0.18 -
GData 21.275/21.91 20100601 2010-06-01 7.08 -
ViRobot 20100601 2010.06.01 2010-06-01 0.36 -
Ikarus T3.1.01.84 2010.06.01.75973 2010-06-01 6.50 AdWare.AdSpy
JiangMin 13.0.900 2010.05.31 2010-05-31 1.19 -
Kaspersky 5.5.10 2010.06.01 2010-06-01 0.13 -
KingSoft 2009.2.5.15 2010.6.1.18 2010-06-01 0.60 Win32.Troj.Generic.316720
McAfee 5400.1158 6000 2010-06-01 15.85 -
Microsoft 1.5802 2010.06.01 2010-06-01 6.43 -
Norman 6.04.12 6.04.00 2010-05-31 4.01 -
Panda 9.05.01 2010.05.31 2010-05-31 2.02 -
Trend Micro 9.120-1004 7.212.15 2010-06-01 0.00 -
Quick Heal 10.00 2010.06.01 2010-06-01 1.60 -
Rising 20.0 22.50.01.03 2010-06-01 0.98 -
Sophos 3.07.1 4.53 2010-06-01 3.72 -
Sunbelt 3.9.2424.2 6385 2010-06-01 8.15 Pinball Corporation. (v)
Symantec 1.3.0.24 20100531.003 2010-05-31 0.05 -
nProtect 20100601.02 8538506 2010-06-01 7.89 -
The Hacker 6.5.2.0 v00290 2010-05-30 0.32 -
VBA32 3.12.12.5 20100601.1109 2010-06-01 3.63 -
VirusBuster 4.5.11.10 10.126.61/2035674 2010-06-01 2.52 -

Attachments:

:thumbup:
Good job. A couple of more things before we finish.
First we need to clean your system from the tools we've used, remove all previous restore points as they could be infected and create a clean one:

  • Click START then RUN
  • Now type Combofix /uninstall in the runbox and click OK. Note the space between the X and the /, it needs to be there.

🖼Click to load external image (Posted Image)


NEXT


Now to remove most of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.


NEXT



Now let's make some important updates to improve the security:

First update your Java to make your system more secure:

Download the latest version Here save it, do not install it yet.

Java SE Runtime Environment (JRE)JRE 6 Update 20 <–The wording is confusing but this is what you need

  • Go to your Add Remove Programs in the Control Panel and uninstall any previous versions of Java
  • Reboot your computer
  • Install the latest version
You can verify the installation Here

Before I give you my Final Speech do you have any questions?
This is my Closing post:
  • How did I get infected in the first place ?

    Read these links and find out how to prevent getting infected again.

  • Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
  • WhattheTech
  • Grinler BleepingComputer
  • GeeksTo Go
  • Dslreports

You may consider also getting these tools:

Mozilla Firefox Browser
A lot more secure than Internet Explorer

SpywareBlaster
SpywareBlater will block bad sites from installing there junk, No scan to run, just update about once a week and enable all protection.

WinPatrol
Will block any changes to your system and alert you to that change so you can either allow or block that change

Spybot Search and Destroy
Another great program to install, you can use the Immunize feature to block bad websites. If you install this program and also SpywareBlaster, then do not enable the teatimer as they will conflict.

We will keep this thread open for a couple of days. Please post back if you have any problems or questions.
Please post back when you have finished so this thread can be marked "Resolved".


Thank you for your patience and Keep Safe. :wavey:
Ok I already gave you my closing speech but we are not through yet!
Reviewing your log with my teacher we are concerned about this program:

C:\Program Files\HBLite\bin\11.0.181.0\HBLiteSAAX.dll

Do you know or use this program HBLite?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI