Avast WEBforum

Other => Viruses and worms => Topic started by: phydron on September 18, 2012, 06:41:34 PM

Title: Back Door Trojan has Hijacked my computer!!
Post by: phydron on September 18, 2012, 06:41:34 PM
I have a Dell Mini that has downloaded a trojan: HEUR.BackDoor.Win64.Generic as reported by Kasperski Security Scan.
I haven't beeen able to run any other scans. Before this scan, I removed the BIOS battery for 30 mins., replaced the HDD, upgraded the RAM, reinstalled WIN7 Starter, an the virus was still there. I tried to run sysclean, but it wouldn't load.
asMBr loads definitions, then says: Initialize error c000010E-driver not loaded. HiJack this won't run, nor will any
other scan and now Kasperski Security Scan won't load.
Can anyone tell me where to begin?
Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: Pondus on September 18, 2012, 07:43:49 PM
follow the guide and attach the logs. http://forum.avast.com/index.php?topic=53253.0

AdwCleaner
Malwarebytes
OTL
aswMBR


Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: phydron on September 18, 2012, 09:33:59 PM
The only way I can gain access to this machine is to reformat the HDD and remove the BIOS battery.
Is there an easier way?

Thanks
Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: essexboy on September 18, 2012, 09:39:00 PM
Are you able to get into windows to run a programme ?

(https://dl.dropbox.com/u/73555776/RKScan.GIF)   
 
(https://dl.dropbox.com/u/73555776/RKDelete.GIF)     
Please post:    All RKreport.txt text files located on your desktop.
Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: phydron on September 19, 2012, 01:32:18 AM
Here are the files I could get. Malwarebytes wouldn't run, I got a runtime 0 error message. I downloaded it twice,
with the same result.
Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: phydron on September 19, 2012, 01:38:02 AM
Here are the rest:


The RootkitBuster is just for WIW.

Ihave many more RKReport files if you want them.
Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: essexboy on September 19, 2012, 03:14:42 PM
Could you tell me exactly what the current problems are

Aslo delete your current copy of OTL and download the latest version

Download OTL (http://oldtimer.geekstogo.com/OTL.exe)  to your Desktop
(https://dl.dropbox.com/u/73555776/OTL_Main_Tutorial.gif)
netsvcs
BASESERVICES
%SYSTEMDRIVE%\*.exe
/md5start
services.*
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
qmgr.dll
/md5stop
CREATERESTOREPOINT

Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: phydron on September 19, 2012, 05:01:29 PM
Here are the logs you requested:

I hope this is what you wanted, I couldn't find the "attach" file anywhere.

Thanks for what you do, it's really appreciated.
Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: essexboy on September 19, 2012, 07:35:10 PM
At the moment I am seeing no evidence of malware..  What problems are you experiencing ?
Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: phydron on September 20, 2012, 03:39:09 AM
No rootkit scanners can run, Hijackthis halts after ten or twelve lines. I can't stop my interner connection for more than
five minutes without it beguining again, my SD card gets harder and harder to access, until it won't read it at all.

This computer isn't worth the time we've put into it, but I hate to see them win.

Here are a few screen captures, Win7 Starter doesn't come with a capture program.

Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: essexboy on September 20, 2012, 06:08:44 PM
OK lets check the MBR and service files

Download the latest version of TDSSKiller from here (http://support.kaspersky.com/downloads/utils/tdsskiller.exe) and save it to your Desktop.
 
 
(http://dl.dropbox.com/u/73555776/TDSSEnd.JPG)
 
Please copy and paste its contents on your next reply.
Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: phydron on September 20, 2012, 08:02:33 PM
Here's the log you requested:

I'm not sure this is a MBR infection. I replaced the HDD with a new, clean one, replaced the RAM, disconnected the
BIOS battery. The only place a virus could exist under those conditions is the chipset  or CPU, i guess.

Whatever is in this won't let me boot from anything external. Do you have any idea how to defeat that?


Thanks
Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: essexboy on September 20, 2012, 08:34:55 PM
Now this is intriguing, as none of the other scans detected these.  These files will be placed in the TDSSKiller quarantine, once they are there could you scan them with Avast please and let me know the result 

Run TDSSKiller again with the same parameters and select delete for the following :

10:56:24.0477 3740  AHKA ( UnsignedFile.Multi.Generic ) - skipped by user
10:56:24.0477 3740  AHKA ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:56:24.0477 3740  GLJAR ( UnsignedFile.Multi.Generic ) - skipped by user
10:56:24.0477 3740  GLJAR ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:56:24.0493 3740  LNCLZKSLCM ( UnsignedFile.Multi.Generic ) - skipped by user
10:56:24.0493 3740  LNCLZKSLCM ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:56:24.0493 3740  VCOQNW ( UnsignedFile.Multi.Generic ) - skipped by user
10:56:24.0493 3740  VCOQNW ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:56:24.0493 3740  WVYYDMDLSBUEMDH ( UnsignedFile.Multi.Generic ) - skipped by user
10:56:24.0493 3740  WVYYDMDLSBUEMDH ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:56:24.0508 3740  ZKY ( UnsignedFile.Multi.Generic ) - skipped by user
10:56:24.0508 3740  ZKY ( UnsignedFile.Multi.Generic ) - User select action: Skip
Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: phydron on September 20, 2012, 09:46:21 PM
TDSSKiller comes back clean, but HiJackThis still won't run (attached), and RootkitBuster still reports malware, I know some
of it is false, an Rootkit revealer still won't run (It runs fine on a clean machine).
Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: essexboy on September 20, 2012, 09:49:42 PM
Those files did not show in the TDSSKiller re-run ?

Have you right clicked Hijackthis and selected run as Admin ?
Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: phydron on September 20, 2012, 10:34:30 PM
They didn't show up in TDSSkiller.

Run as administer doesn't make any difference in Hijackthis.
Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: essexboy on September 20, 2012, 11:26:35 PM
OK lets see if Combofix will see them

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1  (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here  (http://forums.whatthetech.com/How_Disable_your_Security_Programs_t96260.html&pid=494216#entry494216)
(http://img.photobucket.com/albums/v706/ried7/NSIS_disclaimer_ENG.png)

(http://img.photobucket.com/albums/v706/ried7/NSIS_extraction.png)

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: phydron on September 21, 2012, 03:38:46 AM
I've tried everyway I can think of to run HijackThis. I've used it for several years and never had a problem before.

Here's the TDSSKiller log:

Whatever this is, the more I'm online the worse it gets. I reformatted the HDD, changed the RAM, and disconnected the BIOS battery. I don't see how it's possible, but this bug has to be in flash memory somewhere.

If we can't find it soon, a used MOBO is only $30.00 although I hate to give in. I'd like to thank you for your patience and
help, I can see from the forum that you're very busy.

Thanks again.
Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: essexboy on September 21, 2012, 02:38:26 PM
Weird there are not there... Did you run Combofix ?

Also Hijackthis is no longer relevant with the current malware especially 64 bit systems
Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: phydron on September 21, 2012, 03:31:10 PM
Here is the HijackThis log. I think whatever is on this PC, it's keeping Hijackthis from going past #23.

Reading other posts on this forum, I can see how busy you are, so I think I'll buy another M/B for $30.00

and admit defeat. I use this machine for ham radio logging and need it.

If you have any further ideas, let me know.

If I leave this on the internet, It becomes almost unusable.

Thanks for your help, I've learned a lot.
Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: essexboy on September 21, 2012, 03:49:39 PM
23 is the last HJT entry http://www.bleepingcomputer.com/tutorials/how-to-use-hijackthis/#O24Diag

For malware to enter the BIOS is something I have not yet come across

My final idea would be to run Combofix to see if it can locate any suspect drivers
Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: phydron on September 22, 2012, 12:41:12 AM
Now, when I try to almost anything, a dialog box says"Illegal operation attempted on a registry key that has been marked for
deletion" or "Unspecified error". I did get ComboFix to run before it got too bad.
Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: essexboy on September 22, 2012, 01:24:33 PM
A reboot will cure that, Combofix failed to release the registry

OK combofix saw them

1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
3. Open notepad and copy/paste the text in the quotebox below into it:
Quote
File::
c:\users\norm\AppData\Local\Temp\QXZYMYYPCG.exe
c:\users\norm\AppData\Local\Temp\SQKJFMCSF.exe
c:\users\norm\AppData\Local\Temp\XCPIQEYC.exe
c:\users\norm\AppData\Local\Temp\YVD.exe

Driver::
QXZYMYYPCG
SQKJFMCSF
XCPIQEYC
YVD
Save this as CFScript.txt, in the same location as ComboFix.exe
(http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif)

Refering to the picture above, drag CFScript into ComboFix.exeWhen finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.

Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: phydron on September 22, 2012, 04:28:57 PM
I ran ComboFix twice. I hope that's not counterproductive.
Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: essexboy on September 22, 2012, 04:40:25 PM
Did you create the CFScript text file and drag and  drop onto the combofix icon ?  As combofix is not reporting that as happening
Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: phydron on September 22, 2012, 05:41:30 PM
I think I got it right this time.
Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: essexboy on September 22, 2012, 06:16:11 PM
Two more

1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
3. Open notepad and copy/paste the text in the quotebox below into it:
Quote
File::
c:\users\norm\AppData\Local\Temp\ESFODCY.exe
c:\users\norm\AppData\Local\Temp\LLT.exe

Driver::
ESFODCY
LLT
Save this as CFScript.txt, in the same location as ComboFix.exe
(http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif)

Refering to the picture above, drag CFScript into ComboFix.exeWhen finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.

Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: phydron on September 22, 2012, 08:00:31 PM
Here's the latest.
Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: essexboy on September 22, 2012, 09:02:39 PM
OK that appears to be all the bad drivers.  Is there any change in the computer ?
Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: phydron on September 22, 2012, 11:01:00 PM
It seems much better, Rootkit revealer still won't run (it does on another laptop) and RootkitBuster found two errors
and deleted them, but still displays mythical errors. I know they're not real, but the fact that they're still there
bothers me.

Correction: Rootkit revealer does NOT run on a Win 7 machine---My error.
Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: essexboy on September 23, 2012, 12:01:11 AM
Quote
Operating System Hook ZwAddBootEntry; hooked by C:\Windows\System32\Drivers\aswSnx.SYS
Is this the rootkit buster one you are concerned about ?  As it is the Avast sandbox
Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: phydron on September 23, 2012, 04:11:31 AM
Well, I'll guardedly say we may have fixed this PC. The only problem I still have is that I had the HDD out and reformatted
it with/u, replaced the system RAM with a new stick, removed the motherboard and took the BIOS battery out and this
malware was still there. I did all this twice to be sure. It will be a while until I put anything important on here, but it's
been working properly most of the day.

I'd like to thank you for all your help, time and effort and expertise. You've done me a great favor. If you ever have any
Ham radio questions, be sure to ask.
Title: Re: Back Door Trojan has Hijacked my computer!!
Post by: essexboy on September 23, 2012, 01:23:33 PM
Subject to no further problems   :)

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems 

Now the best part of the day ----- Your log now appears clean  :thumbsup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset  System Restore points:

Run OTLRemove ComboFix

Run OTL and hit the cleanup button.  It will remove all the programmes we have used plus itself. 

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
SPRING CLEAN

To manually create a new Restore Point
 Now we can purge the infected ones
Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:
(http://img233.imageshack.us/img233/7729/mbamicontw5.gif)
Malwarebytes (http://www.malwarebytes.org/mbam-download.php).  Update and run weekly to keep your system clean

Download and install FileHippo update checker (http://www.filehippo.com/updatechecker/) and run it monthly it will show you which programmes on your system need updating and give a download link

It is critical to have both a firewall and anti virus to protect your system and to keep them updated. To keep your operating system up to date visit
To learn more about how to protect yourself while on the internet read our little guide  How did I get infected in the first place ? (http://www.geekstogo.com/forum/topic/225044-preventing-malware-and-safe-computing/)

Keep safe  :wave: