Avast started informing me tonight that I was infected with Win32:Ramnit-B and began sending some files to the chest. It then started telling me I was infected with VBS:ExeDropper-gen[trj] and began sending a lot of files to the chest. Avast has stopped alerting now but I’d still like some advice over what to do next. I’ve run a scan with MBAM and followed the instructions in the sticky on here. The log is below:
T start with - Run MBAM again and this time when the scan is complete, all detections should have a check mark in the box to the left of the entry, leave them selected (or select if not selected). At the bottom of the window there is a button, Remove Selected, click that and the items will be removed.
I did click remove selected on MBAM, but that was after that log had been created. It said the system would need to be rebooted before the infected stuff would be deleted. Should I reboot? I saw some recommendations in other topics not to turn off the system during whilst it’s infected.
Dr.Web scan’s about 60% of the way through now so I’ll post that soon.
Yes you need to reboot, some elements may not be able to be removed when they are active in windows, hence the need to reboot.
I’m not familiar with the DrWeb Scan but I would have though that it could be saved in a different format.
The .csv file is basically a text file, that can be opened in a database or something like MS Excel, a spread sheet. So you could try saving a copy (save as) file-name.txt rather than file-name.csv. That should be accepted for attachment, but I don’t know if it might mess with the format, but it is worth a try.
The MBAM one is showing remnants in the registry (and no memory module loaded), after the actual files were removed. The registry entry without the file is pretty much inert, but best removed as you have done. Do a search for this file C:\Users\Lewis\AppData\Local\dbmspr.dll and report if it is present.
Lots of strange stuff in the Stationery folder, whilst there might be a legitimate use for Visual Basic scripts, but in this form I think they are suspect at least. Since DrWeb has moved them and your avast is no longer alerting, I would just monitor your system activity for anything strange.
Anything else that you are seeing out of the ordinary ?
Do you have an active desktop set-up as that would be the only reason I would think there would need to be a desktop.ini file, but there shouldn’t be two of them, windows should stop duplicate names.
The .ini file is a text file and you could right click on it and Open with Notepad and examine the contents (if not personal you could paste them into a post), to see if it was/is trying to run any files etc.
I don’t have an active desktop set=up to my knowledge. The contents of the two files are below:
[.ShellClassInfo]
LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21799
[LocalizedFileNames]
Norton Internet Security.lnk=@C:\PROGRA~1\NORTON~2\Branding\muis.dll,-102
Microsoft Office - 60 Day Trial.lnk=@C:\PROGRA~1\MIDDD5~1\mui\oaa.dll,-103
HP Support Assistant.lnk=@C:\Workspaces\HPAssistant\Dev\HPSFSetup\SupportExes\HelpDTICO.dll,-101
The first one:
Do you have an HP system (looks like it) ?
The MS Office and Norton references may have come pre-installed on the HP system.
This one looks sort of legit, but I can’t say for sure so may be redundant now.
The second one:
Looks like a bit of an update on the first, with possible removal of the trial products.
I don’t have an imageres.dll file in my system32 folder (XP Pro).
The may well be redundant, but you don’t want to delete anything for now I would suggest renaming them, e.g. desktopOldHP1.ini and desktopOld2.ini. That way if there is any reference to them i should throw up an error, missing file, etc. and possibly give a clue as to what is making the call to these files (if any).
Those are system hidden files that some tools make unhidden whilst they work
We will now confirm that your hidden files are set to that, as some of the tools I use will change that
[*]Click Start.
[*]Open My Computer.
[*]Select the Tools menu and click Folder Options.
[*]Select the View Tab.
[*]Under the Hidden files and folders heading select Do not show hidden files and folders.
[]Click Yes to confirm.
[]Click OK.