quibowibbler
New member
Hello,
Im afraid to say I have had some money stolen from my online banking account. After trying to update my vista security patches on windows update, I kept getting an error code 80070490.
I saw on another forum that this error *may* be caused by malware, so I installed the free version of Malwarebytes' Anti-Malware, which found 14 thigns, the most alarming one seems to have affected the registry and is called Backdoor.bot .
Now I saw at http://forums.spybot.info/showthread.php?t=50332 someone has managed to get rid of this. I have pasted the mbam-log below:
Malwarebytes' Anti-Malware 1.44
Database version: 3769
Windows 6.0.6001 Service Pack 1
Internet Explorer 8.0.6001.18372
2/21/2010 4:40:42 PM
mbam-log-2010-02-21 (16-40-41).txt
Scan type: Full Scan (C:\|Z:\|)
Objects scanned: 1108326
Time elapsed: 6 hour(s), 4 minute(s), 15 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 13
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> No action taken.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Users\Adam\AppData\Local\av.exe (Malware.Packer.Gen) -> No action taken.
C:\Users\Adam\AppData\Local\Temp\Lssc.exe (Trojan.Hiloti) -> No action taken.
C:\Users\Adam\AppData\Local\Temp\F0D3.tmp (Trojan.Dropper) -> No action taken.
C:\Users\Adam\AppData\Local\Temp\AF14.tmp (Trojan.Backdoor) -> No action taken.
C:\Users\Adam\AppData\Local\Temp\C5AE.tmp (Trojan.Dropper) -> No action taken.
C:\Users\Adam\AppData\Local\Temp\2F22.tmp (Trojan.Dropper) -> No action taken.
C:\Users\Adam\AppData\Local\Temp\4090.tmp (Worm.KoobFace) -> No action taken.
C:\Users\Adam\AppData\Local\Temp\58D9.tmp (Trojan.Dropper) -> No action taken.
C:\Users\Adam\AppData\Local\Temp\76DD.tmp (Trojan.Backdoor) -> No action taken.
C:\Users\Adam\AppData\Local\Temp\88EF.tmp (Trojan.Dropper) -> No action taken.
C:\Users\Adam\AppData\Local\Temp\9FA1.tmp (Trojan.Dropper) -> No action taken.
C:\Users\Adam\AppData\Local\Temp\A591.tmp (Trojan.Dropper) -> No action taken.
C:\Users\Adam\AppData\Local\Temp\D835.tmp (Trojan.Dropper) -> No action taken.
I believe that the processes the malware is running are named differently to those found on the link i provided earlier. If anyone can talk me through the process of finding and removing this it would be an amazing help. I can't afford to format and reinstall vista as I have a huge amount of work saved on my machine.
Im afraid to say I have had some money stolen from my online banking account. After trying to update my vista security patches on windows update, I kept getting an error code 80070490.
I saw on another forum that this error *may* be caused by malware, so I installed the free version of Malwarebytes' Anti-Malware, which found 14 thigns, the most alarming one seems to have affected the registry and is called Backdoor.bot .
Now I saw at http://forums.spybot.info/showthread.php?t=50332 someone has managed to get rid of this. I have pasted the mbam-log below:
Malwarebytes' Anti-Malware 1.44
Database version: 3769
Windows 6.0.6001 Service Pack 1
Internet Explorer 8.0.6001.18372
2/21/2010 4:40:42 PM
mbam-log-2010-02-21 (16-40-41).txt
Scan type: Full Scan (C:\|Z:\|)
Objects scanned: 1108326
Time elapsed: 6 hour(s), 4 minute(s), 15 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 13
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> No action taken.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Users\Adam\AppData\Local\av.exe (Malware.Packer.Gen) -> No action taken.
C:\Users\Adam\AppData\Local\Temp\Lssc.exe (Trojan.Hiloti) -> No action taken.
C:\Users\Adam\AppData\Local\Temp\F0D3.tmp (Trojan.Dropper) -> No action taken.
C:\Users\Adam\AppData\Local\Temp\AF14.tmp (Trojan.Backdoor) -> No action taken.
C:\Users\Adam\AppData\Local\Temp\C5AE.tmp (Trojan.Dropper) -> No action taken.
C:\Users\Adam\AppData\Local\Temp\2F22.tmp (Trojan.Dropper) -> No action taken.
C:\Users\Adam\AppData\Local\Temp\4090.tmp (Worm.KoobFace) -> No action taken.
C:\Users\Adam\AppData\Local\Temp\58D9.tmp (Trojan.Dropper) -> No action taken.
C:\Users\Adam\AppData\Local\Temp\76DD.tmp (Trojan.Backdoor) -> No action taken.
C:\Users\Adam\AppData\Local\Temp\88EF.tmp (Trojan.Dropper) -> No action taken.
C:\Users\Adam\AppData\Local\Temp\9FA1.tmp (Trojan.Dropper) -> No action taken.
C:\Users\Adam\AppData\Local\Temp\A591.tmp (Trojan.Dropper) -> No action taken.
C:\Users\Adam\AppData\Local\Temp\D835.tmp (Trojan.Dropper) -> No action taken.
I believe that the processes the malware is running are named differently to those found on the link i provided earlier. If anyone can talk me through the process of finding and removing this it would be an amazing help. I can't afford to format and reinstall vista as I have a huge amount of work saved on my machine.