Author Topic: How to remove Bot  (Read 4320 times)

0 Members and 1 Guest are viewing this topic.

jdbaok

  • Guest
How to remove Bot
« on: July 22, 2009, 06:08:54 PM »
I have been using BotHunter to determine whether or not I have an infected PC. BotHunter appears to have identified a bot:

DECLARE BOT
    88.214.203.109 (2) (11:50:23.634 EDT)
   
   event=1:2406027 (2) {tcp} E8[rb] ET RBN Known Russian Business Network Monitored Domains (28)
       
   2208->80 (11:50:23.634 EDT)
       
   2280->80 (11:51:42.860 EDT)
       

tcpslice 1248277714.873 1248277714.874 inputFile.tcpd | tcpdump -r - -w outputFile.tcpd 'host 192.168.2.100'


Avast has not found it...how do I go about eliminating this bot?

Offline nmb

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3054
Re: How to remove Bot
« Reply #1 on: July 22, 2009, 06:12:22 PM »
Hello jdbaok,

Get Hijack this from here: http://www.filehippo.com/download_hijackthis/download/8571e06e5eb8ab03c649f3b5d647c599/

install and run.

post the log.

jdbaok

  • Guest
Re: How to remove Bot
« Reply #2 on: July 22, 2009, 06:18:55 PM »
Hope you are not a spammer ;D

I ran the log but it is too big to post. What should I be looking for? Or what specific section do you want to see?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89033
  • No support PMs thanks
Re: How to remove Bot
« Reply #3 on: July 22, 2009, 06:23:41 PM »
Then attach the log file (Additional Options) it generates or split the contents of the log over two or more posts.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

jdbaok

  • Guest
Re: How to remove Bot
« Reply #4 on: July 22, 2009, 06:51:17 PM »
OK - here it is.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89033
  • No support PMs thanks
Re: How to remove Bot
« Reply #5 on: July 22, 2009, 08:21:30 PM »
First you have tools to tell if you have a bot but noting to stop one getting established, e.g. an active firewall.

You don't appear to have an active firewall - It should be capable of blocking unauthorised outbound Internet Connections.
Whilst the windows XP firewall is usually good at keeping your ports stealthed (hidden) it provides no outbound protection and you should consider a third party firewall.

Any malware that manages to get past your defences will have free reign to connect to the internet to either download more of the same, pass your personal data (sensitive or otherwise, user names, passwords, keylogger retrieved data, etc.) or open a backdoor to your computer, so outbound protection is essential.

Other than that I don't see anything obvious, but there is a possibility that HJT isn't seeing everything that is running. I have no experience of BotHunter so I don't know if this is an inbound attack detection or an outbound connection attempt and it really doesn't give much information to work with, certainly not for me.

If you haven't already got this software (freeware), download, install, update and run it and report the findings (it should product a log file).

Don't worry about reported tracking cookies they are a minor issue and not one of security, allow SAS to deal with them though. - See http://en.wikipedia.org/wiki/HTTP_cookie.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

jdbaok

  • Guest
Re: How to remove Bot
« Reply #6 on: July 23, 2009, 04:39:53 AM »
You note that I am not running a firewall - but if I go to the control panel and click on the firewall it says that it is running. I thought it was running. The bot must be spoofing me.
Thanks for your help. Looks like I'll be working on this for a while.

spg SCOTT

  • Guest
Re: How to remove Bot
« Reply #7 on: July 23, 2009, 11:40:05 AM »
First you have tools to tell if you have a bot but noting to stop one getting established, e.g. an active firewall.

You don't appear to have an active firewall - It should be capable of blocking unauthorised outbound Internet Connections.
Whilst the windows XP firewall is usually good at keeping your ports stealthed (hidden) it provides no outbound protection and you should consider a third party firewall.

Any malware that manages to get past your defences will have free reign to connect to the internet to either download more of the same, pass your personal data (sensitive or otherwise, user names, passwords, keylogger retrieved data, etc.) or open a backdoor to your computer, so outbound protection is essential.


What DavidR was saying is that the XP firewall is not capable enough to protect you and you should consider another, 3rd party one that is better at protecting you.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89033
  • No support PMs thanks
Re: How to remove Bot
« Reply #8 on: July 23, 2009, 02:25:51 PM »
You note that I am not running a firewall - but if I go to the control panel and click on the firewall it says that it is running. I thought it was running. The bot must be spoofing me.
<snip>

That isn't what I said (emphasis made in the quoted text), I said "You don't appear to have an active firewall - It should be capable of blocking unauthorised outbound Internet Connections."

The XP firewall doesn't have that capability as I also said "Whilst the windows XP firewall is usually good at keeping your ports stealthed (hidden) it provides no outbound protection."
« Last Edit: July 23, 2009, 02:28:17 PM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security