This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Trojan Horse Back Door Generic

164 min read

This thread's last reply is from January 9, 2012, 11:06 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

Hi Jeff,

"jja1313" wrote:Here you go. I can't thank you enough for all your help.
No problem , glad I could help 8)

The logs showed just a few more files left. Once we get them all I will issue final instructions to cleanup quarantined items and tighten up the machines security.

Re-run Grantperms
  • Locate the Grantperms folder you extracted earlier (it should be on your desktop).
  • Enter the GrantPerms folder & double click GrantPerms.exe to run it.
  • Copy and paste the contents of the codebox below into the whitebox (Do Not include Code:)

c:\\Documents and Settings\HP_Owner\Application Data\Macromedia\Flash Player\localhost\DOCUME~1\HP_Owner\LOCALS~1\Temp\rf.swf
c:\\WINDOWS\system32\config\systemprofile\Application Data\Motive\Acme\plugin\stats\outmsgs\1116987081937.xml
c:\\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\IsolatedStorage\0hnh3l35.myv\2sqf2il1.rl4\StrongName.czm5tyszaplbnspbwrwr5sftif5gm0kk\AssemFiles\framePref.dat
c:\\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\IsolatedStorage\0hnh3l35.myv\2sqf2il1.rl4\StrongName.zm3mix00r4oodf2vo5zlyh1za3feugtg\AssemFiles\MyImagesPrefs.dat
c:\\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\IsolatedStorage\0hnh3l35.myv\2sqf2il1.rl4\StrongName.zm3mix00r4oodf2vo5zlyh1za3feugtg\AssemFiles\MyImagesState.dat
  • Now Click Unlock
  • When it's done, click "OK".
  • Now click List Permissions and post contents of the log file that opens (Perms.txt)
  • A copy of Perms.txt will be saved in the same directory the tool is run.



Re-run Junction
  • Click Start > Run. Copy and paste the contents of the codebox below into the run box.
    (Do Not include Code:) Then click OK:
cmd /c junction -s c:\ >log.txt&log.txt&del log.txt
  • A command window will open and the system will be scanned. (Click Agree to the prompt)
  • Please be patient & wait untill a log file opens in notepad.
  • Copy and paste the contents of that file in your next reply.
GrantPerms by Farbar
Ran by [removed] (administrator) at 2012-01-07 21:57:54

===============================================
\\?\c:\\Documents and Settings\HP_Owner\Application Data\Macromedia\Flash Player\localhost\DOCUME~1\HP_Owner\LOCALS~1\Temp\rf.swf

Owner: BUILTIN\Administrators

DACL(NP)(AI):
BUILTIN\Administrators FULL ALLOW (CI)(OI)(I)
NT AUTHORITY\SYSTEM FULL ALLOW (CI)(OI)(I)
BUILTIN\Users READ/EXECUTE ALLOW (CI)(OI)(I)
NT AUTHORITY\SYSTEM FULL ALLOW (CI)(OI)(IO)(I)
ARNDT\HP_Owner FULL ALLOW (I)
ARNDT\HP_Owner FULL ALLOW (CI)(OI)(IO)(I)


\\?\c:\\WINDOWS\system32\config\systemprofile\Application Data\Motive\Acme\plugin\stats\outmsgs\1116987081937.xml

Owner: BUILTIN\Administrators

DACL(NP)(AI):
BUILTIN\Administrators FULL ALLOW (I)
NT AUTHORITY\SYSTEM FULL ALLOW (I)
BUILTIN\Users READ/EXECUTE ALLOW (I)


\\?\c:\\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\IsolatedStorage\0hnh3l35.myv\2sqf2il1.rl4\StrongName.czm5tyszaplbnspbwrwr5sftif5gm0kk\AssemFiles\framePref.dat

Owner: BUILTIN\Administrators

DACL(NP)(AI):
BUILTIN\Administrators FULL ALLOW (I)
NT AUTHORITY\SYSTEM FULL ALLOW (I)
BUILTIN\Users READ/EXECUTE ALLOW (I)


\\?\c:\\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\IsolatedStorage\0hnh3l35.myv\2sqf2il1.rl4\StrongName.zm3mix00r4oodf2vo5zlyh1za3feugtg\AssemFiles\MyImagesPrefs.dat

Owner: BUILTIN\Administrators

DACL(NP)(AI):
BUILTIN\Administrators FULL ALLOW (I)
NT AUTHORITY\SYSTEM FULL ALLOW (I)
BUILTIN\Users READ/EXECUTE ALLOW (I)


\\?\c:\\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\IsolatedStorage\0hnh3l35.myv\2sqf2il1.rl4\StrongName.zm3mix00r4oodf2vo5zlyh1za3feugtg\AssemFiles\MyImagesState.dat

Owner: BUILTIN\Administrators

DACL(NP)(AI):
BUILTIN\Administrators FULL ALLOW (I)
NT AUTHORITY\SYSTEM FULL ALLOW (I)
BUILTIN\Users READ/EXECUTE ALLOW (I)




Junction v1.06 - Windows junction creator and reparse point viewer
Copyright (C) 2000-2010 Mark Russinovich
Sysinternals - www.sysinternals.com


Failed to open \\?\c:\\hiberfil.sys: The process cannot access the file because it is being used by another process.



Failed to open \\?\c:\\pagefile.sys: The process cannot access the file because it is being used by another process.


...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

.
Failed to open \\?\c:\\Qoobox\BackEnv: Access is denied.


..

...

...

...

...

...

...

...

...

...

...

...

..\\?\c:\\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a: JUNCTION
Print Name : C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790
Substitute Name: C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790

\\?\c:\\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a: JUNCTION
Print Name : C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e
Substitute Name: C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e

.

...

...

...

...

...

...

...

...

...

...

...

...

...

...
Hi Jeff,

Congratulations your PC is now feee from infection 8) Follow the below steps to remove quarantined items and tighten your systems security.


Step 1 - Clean up with OTL
  • Double-click OTL.exe
  • Click the CleanUp! button
  • Select Yes when the Begin cleanup Process? Prompt appears
  • If you are prompted to Reboot during the cleanup, select Yes
  • The tool will delete itself once it finishes, if not delete it by yourself

Note: If you receive a warning from your firewall or other security programs regarding OTL attempting to contact the internet, please allow it to do so.


Step 2 - Uninstall Combofix
  • Click on Start >> Run...
  • Now type in ComboFix /Uninstall into the box and click OK.
  • Note the space between the X and the /Uninstall, it needs to be there.

The above procedure will reset your System Restore and clear out the backups and quarantines created during the course of this fix.

Step 3 - Anti Virus
Here are some programs I would reccomend instead of AVG. Install one of these and then uninstall AVG.



Step 4 - Security Check
  • Please download Security Check by screen317 from one of the links below:
    • Link 1
    • Link 2
  • Save it to your Desktop.
  • Double click SecurityCheck.exe, then follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt
  • Please post the contents of that document.



Additional Security Tips.
Update your Antivirus programs and other programs regularly.
Secunia Personal Software Inspector - Copyright © Secunia. This app will monitor programs on your computer for known vulnerabilities. You can set it to auto-update for you, or just prompt you if an update is available. I highly recommend it.
F-secure Health Check - Copyright © F-Secure Corporation. F-Secure Health Check is a free application that tells you if your computer is protected and helps you fix possible security issues.

Visit Microsoft often
Keep on top of critical updates, as well as other updates for your computer.
How to configure and use Automatic Updates in Windows XP
Using Windows Update for Windows XP
Microsoft Update Home

Read, stay informed.
To help minimize the chances of becoming re-infected, please read.
Computer Security - a short guide to staying safer online

Please let me know that you completed the cleanup steps, reviewed the rest of the post. Once I receive your reply, I will provide further instructions on the SecurityCheck scan if neeeded. The topic will then be closed as resolved.
THANK YOU


Results of screen317's Security Check version 0.99.24
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
avast! Free Antivirus
AVG 2012
ESET Online Scanner v3
```````````````````````````````
Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware
CCleaner
Java(TM) 6 Update 30
Adobe Flash Player ( 10.3.183.7) Flash Player Out of Date!
Adobe Reader X (10.1.1)
Mozilla Firefox (x86 en-US..)
````````````````````````````````
Process Check:
objlist.exe by Laurent

Norton ccSvcHst.exe
WinPatrol winpatrol.exe
AVG avgwdsvc.exe
AVG avgtray.exe
AVG avgnsx.exe
AVAST Software Avast AvastSvc.exe
AVAST Software Avast AvastUI.exe
BillP Studios WinPatrol winpatrol.exe
``````````End of Log````````````
Hi Jeff,

I can see you have installed Avast Anti-Virus, good! You also still have AVG installed, this needs to be uninstalled. Your flash player is also out of date, leaving you vulnerable to re-infection.

multiple Anti Virus programs
AVG 2012
Avast Anti Virus

  • Anti-virus programs take up an enormous amount of your computer's resources when they are actively scanning your computer.
  • Having two anti-virus programs running at the same time can cause your computer to run very slow, become unstable and even, in rare cases, crash.
  • Please remove one of them.
    • Click on start
    • Then Run
    • In the open text entry box please copy/paste appwiz.cpl Then click enter.
    • Press the "Remove" or "Change/Remove"...button to uninstall one of the programs listed above.
    • Also please Uninstall Adobe Flash Player


You can get the latest version of Flash here http://get.adobe.com/flashplayer/

Please let me know you have completed these steps so this topic can be closed. Safe Surfing!

diver79.
Hello Diver79,

AVG has been completely uninstalled. A link checker was still hanging around. I have also installed the current version of Adobe Flash.

Thanks again for all your help. You are miracle workers. I looked at applying for the MW University, but didn't know if I had the time. We appreciate your dedication.

Thanks,
Jeff
As your problems appear to have been resolved,