I'm getting multiple windows popping up with security alerts, activate antivirus, virus alert: file wuauclt.exe is damaged, etc.
I've copied hijackthis.exe and DDS.scr to the desktop and tried to run, but the windows get shut as soon as they start opening.
I can't get files to post for your diagnosis.
Is this system beyond recovery? Would it help to try running in safe mode?
Thanks
My name is NoodleTech. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
The fixes are specific to your problem and should only be used for the issues on this machine.
Do not delete anything unless instructed to.
DO NOT use tools such as ComboFix without supervision.
Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not mean that everything is clean.
It's often worth reading through these instructions and printing them for ease of reference.
If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
Please reply to this thread. Do not start a new topic.
Print out these instructions as we may need to close every window that is open later in the fix.
It is possible that the infection you are trying to remove will not allow you to download files on the infected computer. If this is the case, then you will need to download the files requested in this guide on another computer and then transfer them to the infected computer. You can transfer the files via a CD/DVD, external drive, or USB flash drive.
Do not reboot your computer after running rkill as the malware programs will start again.
Please download and run the following tool to help allow other programs to run. (courtesy of BleepingComputer.com)
There are 5 different versions. If one of them won't run then download and try to run the other one. If you get a popup warning you that the file you are trying to run is infected, leave the warning open and run the file again.
Vista and Win7 users need to right click and choose Run as Admin
You only need to get one of them to run, not all of them.
rkill.exe
rkill.com
rkill.scr
WiNlOgOn.exe
uSeRiNiT.exe
Do not reboot your computer after running rkill as the malware programs will start again.
Please download exeHelper to your desktop.
Double-click on exeHelper.com to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of exehelperlog.txt (Will be created in the directory where you ran exeHelper.com, and should open at the end of the scan)
pop-up window from DDS states "This tool does not support your operating system"
The computer is running Windows 7 Home Premium
I installed Malware Bytes but couldn't update because the computer isn't hooked to internet right now
Here's the log from quick scan:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 5363
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
4/19/2011 9:22:34 PM
mbam-log-2011-04-19 (21-22-34).txt
Scan type: Quick scan
Objects scanned: 156423
Time elapsed: 2 minute(s), 16 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\Users\psychic\AppData\Local\Temp\8v0C.exe (Trojan.Hiloti) -> Quarantined and deleted successfully.
c:\Users\psychic\Desktop\uSeRiNiT.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
c:\Users\psychic\Desktop\WiNlOgOn.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
One or more of the identified infections was a Backdoor trojan.
This can allow hackers to potentially remotely control your computer, steal critical system information and download and execute files.
If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.
Though the trojan has been identified and killed, because of it's backdoor functionality, your PC might be compromised to a point that there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:
How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
When Should I Format, How Should I Reinstall
I can still clean this machine but I can't guarantee that it will be 100% secure afterwards. If after careful consideration you have decided to move forward with cleanup then please proceed as I have outlined below.
Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.
Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.
Please go here then click on: [external image: Posted Image]
Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install. All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.
Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
When prompted allow the Add-On/Active X to install.
Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
Now click on Advanced Settings and select the following:
Scan for potentially unwanted applications
Scan for potentially unsafe applications
Enable Anti-Stealth Technology
Now click on: [external image: Posted Image]
The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
When completed the Online Scan will begin automatically.
Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
Now click on: [external image: Posted Image]
Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
Copy and paste that log as a reply to this topic.
Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
Here's log from ESET scan:
C:\Users\psychic\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1\68ac45c1-5fb35f73 a variant of Java/TrojanDownloader.OpenConnection.DT trojan
C:\Users\psychic\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\24432f51-5a68acfb a variant of Java/TrojanDownloader.OpenConnection.MU trojan
C:\Users\psychic\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\46cde3b2-5738cc56 a variant of Java/TrojanDownloader.OpenConnection.DT trojan
C:\Users\psychic\Desktop\test.exe Win32/Adware.SpywareProtect2009 application
Note: I did not delete the files listed. Should I?
We will remove them with ComboFix and by clearing your Java cache.
Copy/paste the text in the Codebox below into notepad:
Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:
Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.
File::
C:\Users\psychic\Desktop\test.exe
Save this file to your desktop, Save this as "CFScript"
Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
Updating Java:
Download the latest version of Java Runtime Environment (JRE) 6 Update 24.
Scroll down to where it says "The Java SE Runtime Environment (JRE) allows end-users to run Java applications".
Click the "Download" button to the right.
In the pull down menu next to Platform select Windows
Check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement"
Click Continue
Click on the link to download Windows Offline Installation and save to your desktop.
Close any programs you may have running - especially your web browser.
Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
Check any item with Java Runtime Environment (JRE or J2SE) in the name.
Click the Remove or Change/Remove button.
Repeat as many times as necessary to remove each Java versions.
Reboot your computer once all Java components are removed.
Then from your desktop double-click on jre-6u24-windows-i586-p.exe to install the newest version.
Now to Clean out the Java cache:
Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
Under Temporary Internet Files, click the Settings… button
click the Delete Files button.
There are three options in the window to clear the cache - Leave all 3 Checked
Downloaded Applets
Downloaded Applications
Other Files
Click OK on Delete Temporary Files Window Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
Noodle-
Thanks for your patience.
I had to shut down to move the computer to connect to the internet for ESET scan and JAVA update.
I don't know if that brought the Trojan back, but while downloading JAVA update I began getting anti-virus pop-ups again.
I had installed AVG, but unfortunately COMBOFIX won't run with that installed.
I'm starting over again and will got through all of the steps you posted.
Hope to post new logs tomorrow.
Thanks again.
Noodle-
Thanks for your patience.
I had to shut down to move the computer to connect to the internet for ESET scan and JAVA update.
I don't know if that brought the Trojan back, but while downloading JAVA update I began getting anti-virus pop-ups again.
I had installed AVG, but unfortunately COMBOFIX won't run with that installed.
I'm starting over again and will got through all of the steps you posted.
Hope to post new logs tomorrow.
Thanks again.