Backdoor:Win32/RDPopen.b

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by n.rochon, Dec 13, 2012.

  1. n.rochon

    n.rochon Private E-2

    Hello all,

    Just want to say thank you in advance for the help. Microsoft Security Essentials keeps popping up saying something along the lines of "Cleaning Items, no action necessary". Windows Firewall also keeps disabling itself, even after re-enabling it. Looking in the history of MSE it shows multiple findings of Backdoor:Win32/RDPopen.b.

    Here are the logs as instructed.

    Hello all,

    Just want to say thank you in advance for the help. Here are the logs as instructed.
     

    Attached Files:

    Last edited by a moderator: Dec 13, 2012
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please ATTACH the requested logs. :major
     
  3. n.rochon

    n.rochon Private E-2

    My apologies.

    As requested..
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not finding much in the way of malware. Let's do this:

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [RUN][SUSP PATH] HKCU\[...]\Run : MusicManager ("C:\Users\Nick\AppData\Local\Programs\Google\MusicManager\MusicManager.exe") -> FOUND
      [RUN][SUSP PATH] HKCU\[...]\Run : Java Updater Module (C:\Windows\Sun\Java\bin\javaw.exe -jar C:\Windows\config\systemprofile\AppData\Local\Google\Update\Manifest\Initial\1e611a00) -> FOUND
      [RUN][ROGUE ST] HKLM\[...]\Run : HPWirelessAssistant (C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden) -> FOUND
      [RUN][SUSP PATH] HKUS\S-1-5-21-449478598-2064282937-4253019286-1001[...]\Run : MusicManager ("C:\Users\Nick\AppData\Local\Programs\Google\MusicManager\MusicManager.exe") -> FOUND
      [RUN][SUSP PATH] HKUS\S-1-5-21-449478598-2064282937-4253019286-1001[...]\Run : Java Updater Module (C:\Windows\Sun\Java\bin\javaw.exe -jar C:\Windows\config\systemprofile\AppData\Local\Google\Update\Manifest\Initial\1e611a00) -> FOUND
      [HJ] HKLM\[...]\System : EnableLUA (0) -> FOUND
      [HJ] HKLM\[...]\Wow6432Node\System : EnableLUA (0) -> FOUND
      [HJ DESK] HKCU\[...]\ClassicStartMenu : {645FF040-5081-101B-9F08-00AA002F954E} (1) -> FOUND
      [HJ DESK] HKCU\[...]\NewStartPanel : {645FF040-5081-101B-9F08-00AA002F954E} (1) -> FOUND
      [HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
      [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Do not reboot your computer yet.

    Now re-run Hitman and have it remove those PUP's

    Reboot and re-run both RogueKiller and Hitman.
    Attach both those logs.

    Also attach the MSE log that shows the infection.
     
  5. n.rochon

    n.rochon Private E-2

    Still showing up in MSE. Here are the logs. Don't remember why I got so many RK logs, but I'm attaching them all just in case.
     

    Attached Files:

  6. n.rochon

    n.rochon Private E-2

    Also, it appears that MSE doesn't generate logs. So here is a screen shot in a word document of the history.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    MSE is doing it's job. Tell me what is happening now.
     
  8. n.rochon

    n.rochon Private E-2

    The firewall continues to turn off, and the popups from MSE continue to show. Otherwise, machine is running ok.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Next time it shows up, run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the new log.
     
  10. n.rochon

    n.rochon Private E-2

    Haven't seen any firewall turning off, but this thing is found in MSE about 20-30 times a minute in the history. Any minute of any hour. Here is the log as requested.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It's not showing up in your logs. Let's have you do this:

    Please download ComboFix to your desktop. Turn off any AV software you have before you run it. Attach the log when finished. Do not do anything while it is running or it may stall the program.
     
  12. n.rochon

    n.rochon Private E-2

    Still showing up in MSE.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    Attach both of these logs into your next reply.
     
  14. n.rochon

    n.rochon Private E-2

    Attached.
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Double-click OTL.exe to start the program.
    • Copy and Paste the following code into the Custom Scans/Fixes textbox. Do not include the word Code
    Code:
    :processes
    :killallprocesses
    :files
    @Alternate Data Stream - 140 bytes -> C:\ProgramData\Temp:EA029835
    :commands
    [PURITY]
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    
    • Then click the Run Fix button at the top.
    • Click the OK button.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. Just close notepad and attach this log form OTL to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
     
  16. n.rochon

    n.rochon Private E-2

    ....
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Is it still happening? I can't find it in your logs.
     
  18. n.rochon

    n.rochon Private E-2

    Yes, still showing up in the log multiple times per minute in MSE.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Double-click OTL.exe to start the program.
    • Copy and Paste the following code into the Custom Scans/Fixes textbox. Do not include the word Code
    Code:
    :processes
    :killallprocesses
    :files
    C:\windows\SysWOW64\lssasr.exe
    :commands
    [PURITY]
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    
    • Then click the Run Fix button at the top.
    • Click the OK button.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. Just close notepad and attach this log form OTL to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  20. n.rochon

    n.rochon Private E-2

    Sorry for the delay! Computer has been running better, not turning off the firewall, BUT....the instance is still showing up in MSE.
     

    Attached Files:

  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't know what to tell you. It is not showing up in any of your logs. Let me consult with my colleagues.
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go into MSE and delete the history. Then tell me if it shows up again.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds