Sorry for the length of this, but I’ve been slack on my malware protection lately, and just got a major infection. I tried cleaning it up on my own, and wanted to be clear on everything that happened and what I did. Thank you in advance for any help and advice you can offer.
I was online the other night going through some old bookmarks and found myself at some. . . "questionable" sites (yes, I should've known better), when my system started bogging down. A message then popped up saying that Windows Firewall had been disabled (since adding a router with a hardware firewall, I never got around to finding a replacement for the free version of ZoneAlarm I had become disappointed with and quit using), and TeaTimer messages began popping up about allowing various changes. Realizing that I had just gotten infected with something, I denied all the TeaTimer requests and turned off my DSL modem to prevent anything else from getting in or out of my system. A fake “scan” and warning that I was infected with various things and needed to purchase something from “System Security” took over my desktop.
I ran SpyBot to try to clean things up, but hadn’t updated it in months (version 1.6.0 I think it was). It found multiple things, including a trojan and some keyloggers, and I had it remove all of them. I also ran a full scan of Avast! (updated that day), which found and removed some things. Rebooting left me with the malware still in control of my desktop, SpyBot would no longer open, and ctrl-alt-del would bring the Windows Task Manager up for just a second before it would disappear. Booting into Safe Mode allowed me to run SpyBot and Avast! again, but still did not remove the System Security hold on my computer. Some of the files found by these two included CNwAQdN.zip, sdra64.exe, and Win32.Agent.pz.
Looking around the areas where problems had been found, I came across a folder under documents and settings that contained the icon for the System Security garbage that had taken over my desktop, so I moved it to the recycle bin and then deleted it permanently. Rebooting brought me to a blank blue screen with nothing but a mouse cursor on it. No icons or taskbar or anything else. Safe Mode was the same except for being a black screen with the Safe Mode tags on it. From that, I found that I could call up the Task Manager and run things from there, so I got into the System Restore and reverted to a save point from the previous week. Everything loaded fine and things seemed normal, so I connected to the internet again and:
1. Updated and ran SpyBot, which found and removed another file related to System Security.
2. Immunized my system again.
3. Downloaded and ran SpywareBlaster
4. Downloaded and ran Malwarebytes Anti-Malware, which found and removed 4 or 5 more infections
5. Downloaded and ran SUPERAntiSpyware, which found and removed several more infections.
Currently, everything appears to be running normally, but reading the forums here has me worried that things may still be hidden in my system. I kept the system offline until after the system restore got my desktop back, and haven’t visited any sites where I had to enter a password or other personal information for fear of that information being stolen.
What I am thinking of doing now is to back up the things I feel are vital (photos, emails, bookmarks, Word files, and maybe a few other things), then reformatting and reinstalling, just in case. Below is my HJT log. Could you please look over it and see if anything appears problematic yet? Also, any idea of the odds any data has been stolen from my system? Finally, how much of a risk is there in transferring the files I mentioned to a clean install? Are there certain types that are safe and others that are not? Thank you so much for any help and guidance you can provide.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:44:40 PM, on 7/22/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal