This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

IRC Bot Virus

68 min read

This thread's last reply is from March 30, 2009, 9:31 AM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

Malwarebytes' Anti-Malware 1.35
Database version: 1904
Windows 5.1.2600 Service Pack 3

3/27/2009 8:58:05 PM
mbam-log-2009-03-27 (20-58-05).txt

Scan type: Full Scan (C:\|E:\|)
Objects scanned: 323878
Time elapsed: 1 hour(s), 55 minute(s), 57 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 19

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\AdwareAlert (Rogue.AdwareAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Program Files\Adobe\Acrobat 8.0\keygen.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Program Files\Alwil Software\Files\License.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{04E171EC-5846-41F5-A207-BE0B1B1F86BB}\RP391\A0088480.dll (Rogue.SpyCleaner) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{04E171EC-5846-41F5-A207-BE0B1B1F86BB}\RP392\A0088500.rbf (Rogue.SpyCleaner) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{04E171EC-5846-41F5-A207-BE0B1B1F86BB}\RP394\A0088531.rbf (Rogue.SpyCleaner) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{04E171EC-5846-41F5-A207-BE0B1B1F86BB}\RP394\A0088543.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{04E171EC-5846-41F5-A207-BE0B1B1F86BB}\RP394\A0088546.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{04E171EC-5846-41F5-A207-BE0B1B1F86BB}\RP394\A0088547.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{04E171EC-5846-41F5-A207-BE0B1B1F86BB}\RP369\A0086219.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Vista\v3.0\Vista sucks donkeys v3.0.exe (Trojan.VB) -> Quarantined and deleted successfully.
C:\Documents and Settings\Clairmonte Newton\Application Data\Desktopicon\eBayShortcuts.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Downloads\_Kaspersky Internet Security keygen.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Downloads\avast! 4.8.1296 Professional Edition Eng+6 keygens\Avast.Pro.4.8.1296.0.ENG\KeyGens\Keygen-CORE\keygen.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Downloads\Acrobat_8_Pro_Keygen\keygen.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Downloads\Super antispyware 4.20\nGen\Keygen.exe (Trojan.Agent) -> Quarantined and deleted successfully.
E:\Serial Numbers\Acrobat_8_Pro_Keygen\keygen.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
E:\Program Files\WinZix\WinZixManager.dll (Rogue.WinZix) -> Quarantined and deleted successfully.
E:\Documents and Settings\Clairmonte\Shared\Serial Numbers\Acrobat_8_Pro_Keygen\keygen.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\winrar 3.40 corporate.exe (Trojan.Agent) -> Quarantined and deleted successfully.
Well, that revealed some interesting things.

How many of the keygens you downloaded did you actually run?

Uninstall ComboFix
  • Disable all your antimalware programs like you did previously
  • Click Start > Run and enter:
    ComboFix /u
  • Click OK
  • ComboFix will now uninstall itself



Install a firewall
There is no firewall installed on your computer!
Either that, or you're using Windows Firewall, which is not a good idea.

Firewalls are programs that monitor incoming and outcoming connections to your computer. Did you know that, just by connecting to the internet, you are being exposed to hundreds of treats immediately? The way to solve this, is to use a firewall, and up-to-date antivirus software.

Windows Firewall only monitors incoming connections. This means that, once you are infected, the malware is free to ask for new instructions, send private data to its creator, or invite its malware buddies to come over. In other words: it's almost as good as no firewall at all.

Download a free for personal use firewall NOW. If you can't find a good one, try one of these:
Online Armor Free
Agnitum Outpost Free



Congratulations!



As far as I can tell, you are CLEAN!





Have a big cup of , sit back & relax, and now please follow a few of the following tips; they will dramatically reduce your chance of getting infected again.
  • Turn on Automatic Updates if you have not done so. It is MANDATORY to keep your Windows updated, otherwise you are vulnerable to exploits! To turn on Automatic Updates: click Start > Control Panel > Security Centre > Automatic Updates.


Below are optional items. They will increase your security, but are not really "needed". That said, I recommend following at least one of these tips.

  • Install WinPatrol from here. Instructions for use are here.

  • Install a custom hosts file. Let's say I have a directory of 640kb's worth of bad sites. Let's say I can make sure you will never be able to access those sites, so you will never get any infection from those sites. It's like blocking a site - without site blocking tools. How would you like to never be able to visit (a lot, but not all of the) malware-infected sites again? Well, now you can!
    First, we must disable a service, as Windows cannot work with a very large hosts file while that service is active. This will not affect anything else.
    The disabling routine:
    • Click Start, then Run
    • Copy and paste the following:
      sc config dnscache start= disabled
    • Click OK

    Next, you can download the custom hosts file from here. Installation instructions can be found there as well.


Please reply to this thread once more so we know it can be archived.

And stay away from cracks and keygens. 99% of them bundle very nasty malware.


If you have any more questions, now is the time to ask :)
I must once again express my gratitude to you for all your assistance over the past weeks. With your help, I now feel confident to attach my PC to the internet again. I have installed Online Armor free, winpatrol and the custom hosts files. I have heeded the error of my ways and will not download keygens again - from here on I will purchase software if I can afford it.

I must confess that I have never heard of 99% of the software you instructed me to download and run! Is there any suggested reading that I could use to increase my knowledge of what's out there?

Once again, Thank You.
Thank you for the warm thankings. You're most welcome. :)

This is a worthy read: viewtopic.php?f=11&t=4959
proscroby