So here's where my Afternoon has gone...
I ran Malwarebytes and this was the results of the first scan:
Code:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4160
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
07/12/2010 12:35:47
mbam-log-2010-12-07 (12-35-47).txt
Scan type: Full scan (C:\|)
Objects scanned: 288335
Time elapsed: 1 hour(s), 26 minute(s), 43 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 4
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 5
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\startup (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\windows update (Backdoor.IRCBot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winlogon.exe (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Documents and Settings\User\Application Data\Microsoft\svchost.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Documents and Settings\User\Application Data\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\Updater.exe (Backdoor.IRCBot) -> Delete on reboot.
C:\Documents and Settings\User\Application Data\Microsoft\System\Services\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\User\Application Data\Microsoft\System\Services\winlogon.exe (Trojan.Agent) -> Quarantined and deleted successfully.
I then updated Malwarebytes (I know I should've done this first!!) and ran again. Here's the results of the second run:
Code:
Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org
Database version: 5260
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
07/12/2010 15:31:51
mbam-log-2010-12-07 (15-31-51).txt
Scan type: Full scan (C:\|)
Objects scanned: 304940
Time elapsed: 2 hour(s), 33 minute(s), 30 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 3
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 4
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\SrvID (Malware.Trace) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Defender (Trojan.Agent) -> Value: Windows Defender -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Windows Defender (Trojan.Agent) -> Value: Windows Defender -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Defender (Trojan.Agent) -> Value: Windows Defender -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\system volume information\_restore{c4030fa9-793c-407b-8559-2270f060e173}\RP312\A0043591.exe (Adware.RelevantKnowledge) -> Quarantined and deleted successfully.
c:\system volume information\_restore{c4030fa9-793c-407b-8559-2270f060e173}\RP312\A0043639.dll (Adware.RelevantKnowledge) -> Quarantined and deleted successfully.
c:\system volume information\_restore{c4030fa9-793c-407b-8559-2270f060e173}\RP312\A0043640.exe (Adware.RelevantKnowledge) -> Quarantined and deleted successfully.
c:\documents and settings\User\application data\data.dat (Stolen.Data) -> Quarantined and deleted successfully.
I also changed my hosts file to add a line with a made up URL.
I shutdown my PC and then rebooted it and the additional line I added to the hosts file was still there.
So I then restarted my PC to get the same result.
I then removed the following lines from my hosts file:
"127.0.0.1 virustotal.com
127.0.0.1 scanner.novirusthanks.org
127.0.0.1 scanner2.novirusthanks.org
127.0.0.1 virusscan.jotti.org
127.0.0.1 virscan.org"
And restarted my PC and the only line in my hosts file was the made up one I added.
So it seems that I have cleaned up this without the need for a full reformat.
I'm going to run Malwarebytes one more time just to see if it finds anything else.
What should my hosts file default settings be?