Author Topic: Possible Tojan  (Read 27136 times)

0 Members and 1 Guest are viewing this topic.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Possible Tojan
« Reply #30 on: November 13, 2007, 11:02:50 PM »
Definitely bagle I will need to look at the winpfind to clear any residue

ecotack

  • Guest
Re: Possible Tojan
« Reply #31 on: November 14, 2007, 11:58:09 AM »
FxBeagle.exe took hours to finish. Next time I'll disable my two data hard drives to speed things up.  Is it safe to delete files I don't want, while infected, again to help speed things along?

Unfortunately FxBeagle.exe said it found nothing.  I'll try again this evening in safe mode.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Possible Tojan
« Reply #32 on: November 14, 2007, 10:37:34 PM »
OK it looks like the symantec fix is getting a bit old

Download SDFix[/color] and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log


ecotack

  • Guest
Re: Possible Tojan
« Reply #33 on: November 14, 2007, 11:28:00 PM »
Thanks!

I had to run Sdfix twice, because I stupidly ran it from a USB drive the first time and it didn’t finish off after the re-boot.

Logs attached.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Possible Tojan
« Reply #34 on: November 14, 2007, 11:42:31 PM »
Ta for the logs

Please re-open HiJackThis and scan.  Check the boxes next to all the entries listed below.

O4 - HKCU\..\Run: [drvsyskit] C:\WINDOWS\system32\drivers\hidr.exe
O23 - Service: W - Unknown owner - D:\TEMP\W.exe (file missing)

Now close all windows other than HiJackThis, then click Fix Checked.  Close HiJackThis. 

THEN

Please download the OTMoveIt http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe by OldTimer.
Save it to your desktop.
Please double-click OTMoveIt.exe to run it.
Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

D:\TEMP\W.exe
C:\WINDOWS\system32\drivers\hidr.exe



Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
Click the red Moveit! button.
Copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it on your next reply with a new Hijack log.
Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.


If you could now follow up with the winpfind

Download WinPFind3u.exe  to your Desktop and double-click on it to extract the files. It will create a folder named WinPFind3u on your desktop.
  • Close ALL OTHER PROGRAMS.
  • Open the WinPFind3u folder and double-click on WinPFind3U.exe to start the program.
  • On the left under drivers services select non-microsoft
  • Under Additional Scans click the checkboxes in front of the following items to select them:
      Reg - Disabled MS Config Items
      Reg - Security Settings
      Reg - Software Policy Settings

  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Use the Add Reply button and Copy/Paste the information back here. I will review it when it comes in. If, after posting, the last line is not < End of Report > then the log is too big to fit into a single post and you will need to split it into multiple posts.


ecotack

  • Guest
Re: Possible Tojan
« Reply #35 on: November 15, 2007, 12:24:05 AM »
Thanks again.  Log atached.

OTMoveit said it couldn't find the files.

ecotack

  • Guest
Re: Possible Tojan
« Reply #36 on: November 15, 2007, 09:12:11 PM »
Avast icon went again, hidr.exe and srosa.sys are back   :(
I think I'll order a new hard disk and re-install windows

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Possible Tojan
« Reply #37 on: November 15, 2007, 09:39:05 PM »
I would wait until essexboy has a chance to review the WinPFind3u log.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Possible Tojan
« Reply #38 on: November 15, 2007, 10:03:36 PM »
Not good news I'm afraid you also had Goldun and Haxdoor as well as bagle and they were all kind of cooperating to stop you getting fixed.  With this fix I am going to kill explorer so you may loose the desktop etc. 

Start WinPFind3U. Copy/Paste the information in the quotebox below into the pane where it says "Paste fix here" and then click the Run Fix button.

Quote
[Kill Explorer]
[Win32 Services - Non-Microsoft Only]
YY -> (W) W [Win32_Own | Disabled | Stopped] -> D:\TEMP\W.exe
[Driver Services - Non-Microsoft Only]
YY -> (Abiosdsk) Abiosdsk [Kernel | Disabled | Stopped] ->
YY -> (abp480n5) abp480n5 [Kernel | Disabled | Stopped] ->
YY -> (adpu160m) adpu160m [Kernel | Disabled | Stopped] ->
YY -> (Aha154x) Aha154x [Kernel | Disabled | Stopped] ->
YY -> (aic78u2) aic78u2 [Kernel | Disabled | Stopped] ->
YY -> (aic78xx) aic78xx [Kernel | Disabled | Stopped] ->
YY -> (AliIde) AliIde [Kernel | Disabled | Stopped] ->
YY -> (amsint) amsint [Kernel | Disabled | Stopped] ->
YY -> (asc) asc [Kernel | Disabled | Stopped] ->
YY -> (asc3350p) asc3350p [Kernel | Disabled | Stopped] ->
YY -> (asc3550) asc3550 [Kernel | Disabled | Stopped] ->
YY -> (catchme) catchme [Kernel | On_Demand | Stopped] -> D:\TEMP\catchme.sys
YY -> (cd20xrnt) cd20xrnt [Kernel | Disabled | Stopped] ->
YY -> (Changer) Changer [Kernel | System | Stopped] ->
YY -> (Cpqarray) Cpqarray [Kernel | Disabled | Stopped] ->
YY -> (dac960nt) dac960nt [Kernel | Disabled | Stopped] ->
YY -> (dpti2o) dpti2o [Kernel | Disabled | Stopped] ->
YY -> (hpn) hpn [Kernel | Disabled | Stopped] ->
YY -> (i2omgmt) i2omgmt [Kernel | System | Stopped] ->
YY -> (i2omp) i2omp [Kernel | Disabled | Stopped] ->
YY -> (ini910u) ini910u [Kernel | Disabled | Stopped] ->
YY -> (kednl6) AVSearch service [Kernel | On_Demand | Stopped] -> %System32%\kednl6.sys
YY -> (lbrtfdc) lbrtfdc [Kernel | System | Stopped] ->
YY -> (mmx432) MMX2 virtualization service [Kernel | Auto | Stopped] -> %System32%\mmx464.sys
YY -> (mmx464) MMX virtualization service [Kernel | System | Stopped] -> %System32%\mmx464.sys
YY -> (ql1080) ql1080 [Kernel | Disabled | Stopped] ->
YY -> (Ql10wnt) Ql10wnt [Kernel | Disabled | Stopped] ->
YY -> (ql12160) ql12160 [Kernel | Disabled | Stopped] ->
YY -> (ql1240) ql1240 [Kernel | Disabled | Stopped] ->
YY -> (ql1280) ql1280 [Kernel | Disabled | Stopped] ->
YY -> (Simbad) Simbad [Kernel | Disabled | Stopped] ->
YY -> (srosa) Megadrv3 [Kernel | System | Stopped] -> %System32%\drivers\srosa.sys
YY -> (sw848b) sw848b [Kernel | Auto | Running] -> %System32%\drivers\sw848b.sys
YY -> (sw878b) sw878b [Kernel | Auto | Running] -> %System32%\drivers\sw878b.sys
YY -> (symc810) symc810 [Kernel | Disabled | Stopped] ->
YY -> (symc8xx) symc8xx [Kernel | Disabled | Stopped] ->
[Files/Folders - Created Within 30 days]
NY -> wintems.exe.ren -> %System32%\wintems.exe.ren
NY -> srosa.sys.ren -> %System32%\drivers\srosa.sys.ren
[Files/Folders - Modified Within 30 days]
NY -> DEBUGSM.INI -> %SystemRoot%\DEBUGSM.INI
NY -> wintems.exe.ren -> %System32%\wintems.exe.ren
NY -> srosa.sys.ren -> %System32%\drivers\srosa.sys.ren
[File String Scan - Non-Microsoft Only]
NY -> @Alternate Data Stream - 0 bytes -> %SystemRoot%\Thumbs.db:encryptable
[Empty Temp Folders]
[Start Explorer]


The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. CLick the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here along with a new WinPFind3u scan.

I will review the information when it comes back in.

Also let me know of any problems you encountered performing the steps above or any continuing problems you are still having with the computer.

THEN follow that up with a combofix run

Download ComboFix from Here or Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall

ecotack

  • Guest
Re: Possible Tojan
« Reply #39 on: November 15, 2007, 11:07:04 PM »
Thanks again, I was just about to say I would wait for your reply, it’s only courteous, but your post beat me to it.

Logs are attached.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Possible Tojan
« Reply #40 on: November 15, 2007, 11:36:58 PM »
OK 'tis nuclear time

Please re-open HiJackThis and scan.  Check the boxes next to all the entries listed below.

O4 - HKCU\..\Run: [drvsyskit] C:\WINDOWS\system32\drivers\hidr.exe
O23 - Service: W - Unknown owner - D:\TEMP\W.exe (file missing)

Now close all windows other than HiJackThis, then click Fix Checked.  Close HiJackThis.  Reboot into safe mode.


1. Please download The Avenger by Swandog46 to your Desktop.
  • Click on Avenger.zip to open the file
  • Extract avenger.exe to your desktop
2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):

Quote
Drivers to unload:
drvsyskit

Files to delete:
C:\WINDOWS\system32\9B3821D7CB.sys
C:\WINDOWS\system32\drivers\hidr.exe
C:\WINDOWS\system32\F5BC36F762.sys


Note: the above code was created specifically for this user.  If you are not this user, do NOT follow these directions as they could damage the workings of your system.


3. Now, start The Avenger program by clicking on its icon on your desktop.
  • Under "Script file to execute" choose "Input Script Manually".
  • Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
  • Paste the text copied to clipboard into this window by pressing (Ctrl+V).
  • Click Done
  • Now click on the Green Light to begin execution of the script
  • Answer "Yes" twice when prompted.
4. The Avenger will automatically do the following:
  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions.  This log file will be located at  C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please copy/paste the content of c:\avenger.txt into your reply along with a fresh HJT log   by using Add/Reply

ecotack

  • Guest
Re: Possible Tojan
« Reply #41 on: November 16, 2007, 12:19:39 AM »
Hit a problem.

It rebooted twice, then after logging into windows I get the error:
Windows – No Disk
Exception Processing Message c0000013 Parameters 75b6bf9c 4 75b6f9c 75b6bf9c

And a cmd window saying:
The system cannot find the file specified.
Could Not Find C:\avenger\*.reg
        1 file(s) copied.
        zip warning: C:/backup.zip not found or empty
  adding: avenger/9B3821D7CB.sys (104 bytes security) (deflated 36%)
  adding: avenger/avenger.txt (188 bytes security) (deflated 72%)
  adding: avenger/backup.reg (188 bytes security) (stored 0%)
  adding: avenger/F5BC36F762.sys (104 bytes security) (stored 0%)

I have left these windows open and run hjt, logs attached.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Possible Tojan
« Reply #42 on: November 16, 2007, 07:31:30 PM »
Ok you can close those windows and delete the following in Hijackthis,and the file on your drive.   It appears that avenger stalled.  However, there is no longer any sign of Bagle 

Please re-open HiJackThis and scan.  Check the boxes next to all the entries listed below.

O4 - HKLM\..\Run: [esdaffjc] C:\ldttwerh.bat

Now close all windows other than HiJackThis, then click Fix Checked.  Close HiJackThis. 

As a final check could you re-run DSS and let me now how your system is running now




ecotack

  • Guest
Re: Possible Tojan
« Reply #43 on: November 18, 2007, 11:19:24 AM »
Thanks again.
Ran HJT, but O4 - HKLM\..\Run: [esdaffjc] C:\ldttwerh.bat wasn’t listed.

I connected the network cable, the status says connected, but no packets have been sent or received.  I can’t connect to the internet or local computers on the same network, I can’t even ping the router.

I tried winsockxpfix but that didn’t help.  I have checked all the usual IP settings and windows firewall is disabled. Any ideas?

DSS log attatched.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Possible Tojan
« Reply #44 on: November 18, 2007, 03:23:19 PM »
Well on the bright side DSS shows no problems.   I see you have comodo firewall. 

Have you allowed Ashwebserve access ? 

Have you tried it with Avast paused