Loaded with trojans: Help please

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jcaitlan, Aug 31, 2005.

  1. jcaitlan

    jcaitlan Private E-2

    My laptop is running Windows 2000 S/P4. It's losing the broadband connection frequently, and appears to have unauthorized processes running in the background.

    I've completed the virus removal checklist listed in this Forum, including:

    1) Disabled GoBack

    2) Enabled viewing of hidden files/extensions

    3) Booted into Safe mode and ran Bitdefender and RAV Antivirus (logs available if needed.) Discovered 12 trojan viruses in about 50 files.

    4) Cleaned drive with CCleaner, and ran Ad-Aware SE and Spybot (my regular tools) to identify and clean up spyware. (None found.) Couldn't figure out how to install the VX2 plug-in, but does it really impact trojan removal?

    5) Ran the secondary tools: CWshredder, Kill2Me, about:Buster, HSremove, SpywareBlaster, stinger

    6) Ran additional antivirus tools in normal mode: a-squared StartCenter, Trojan Remover, TrendMicro, and Avast. Not much impact. TR found a single virus (which was not listed on Bitdefender or RAV scans) and removed it. Did not run ADS Spy.

    7) Ran HiJackThis and saved log.

    I tried to do some initial research on the trojan viruses that were identified by Bitdefender to identify alternate methods of cleaning, but not much luck so far.

    Assuming the infected files identified are not false positives, any suggestions for the next step?
     
  2. jcaitlan

    jcaitlan Private E-2

    Re: Loaded with trojans: Addl info

    Forgot to mention that I run have run Norton Firewall and Norton Systemworks / Antivirus the past couple of years, currently have the 2005 version installed, and do full system AV scans twice weekly.

    This problem has been around for the past year, but this is my laptop and I use it off-line 95% of the time, so the problem hasn't been obvious (except for the fact that the hard drive is constantly active most of the time.) I'm starting to get back on the road now, and need my laptop to connect to the Internet reliably.

    Thanks again to anyone who might have the time to help me on this. I'm the local PC guru for my extended family, and spend my vacations cleaning up their infected machines, so I know how much effort goes into this. I just don't have enough savvy to clean up trojans right now.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Loaded with trojans: Addl info

    Please follow the below steps exactly:



    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  4. jcaitlan

    jcaitlan Private E-2

    Ran HJT 1.99.1 and have attached the log, as requested. Thanks much.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your HJT log does not reveal any problems.

    What problem processes are you referring to? What did BitDefender report?

    When you say "the broadband connection frequently". What does this mean exactly? What kind of connection do you have (dial-up, cable, dsl ...)?
     
  6. jcaitlan

    jcaitlan Private E-2

    Bitdefender scan lists the following viruses:

    Backdoor.IRC.Zcrew
    Backdoor.Irc.Flood.AO
    Trojan.Fluxay.A
    Backdoor.Pipecmd.A
    Backdoor.Sdbot.P
    Trojan.Flood.22016
    Backdoor.IRC.Bnc.l
    IRC-Worm.Momma.A
    Backdoor.GTSE.1.0 (BAT)
    Backdoor.SDBot.604487D6

    Most of the infected files are in the System/AtapiDrv directory, especially the wserver.exe file (which is an obvious problem.) I've found a couple of wserver.exe files in different directories, but didn't want to delete them in a haphazard fashion. I've attached the bitdefender scan file.

    My network link is cablemodem. I lose connectivity several times a day for hours at a time. I see lots of CPU and disk I/O activity even when no user processes are active. This activity goes quiet after you disconnect the network link, and resumes when you restablish connectivity.

    I'm still assuming I have 1 or more current Trojan virus infections, and perhaps the remnants of former infections.

    Norton AV 2005 is not showing any infections during my weekly scans.

    Thanks again for the help and guidance.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach the BitDefender log. Also if RAV found anything, attach that log too.

    Did you run Stinger (in safe mode)? It should detect and remove Netsky files like wserver.exe.

    You could also try running: avast! Virus Cleaner Tool
     
  8. jcaitlan

    jcaitlan Private E-2

    I attached the Bitdefender scan log earlier, but it was html and perhaps you couldn't open it. I've saved it as a text file, and attached both it and the RAV scan log.

    I ran both Stinger & avast in Safe mode last week and repeated the scans again today. Neither identified nor removed the netsky infected files. Strange, eh?
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually you did not attach it before. You cannot attach html files.

    And this time you did not attach text files, you attach Word document files.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure you did not load some kind of drivers on your system related to this AtapiDrv folder stuff. It is strange that they files woud also appear in the C:\Drivers folder.

    Try doing the following, look for the below files and rename them as indicated:

    C:\DRIVERS\wserver.exe <--- rename to wserver.xxx
    C:\WINNT\system32\AtapiDrv\wserver.exe <--- rename to wserver.xxx
    C:\WINNT\system32\bc.exe <--- rename to bc.xxx


    Then reboot your system and let me know if you get any kind of error messages.
    Also rerun the Bitdefender scan now and attach its log.
     
  11. jcaitlan

    jcaitlan Private E-2

    Renamed the 3 wserver.exe files to wserver.exe.xxx, and rebooted into Safe mode; no errors. Then Normal mode; no errors.

    The only drivers I loaded were for an HP Deskjet printer and an IBM Thinkpad CD-RW drive. However, the dates on the AtapiDrv files are six months earlier than the CD-RW installation, so

    Re-ran Bitdefender 8. Scan attached. 10 viruses in 20 different files.

    I've tried to upload the scan log for the past 30 minutes using .log, .txt, and .doc files. I keep getting an error msg that the document is empty. (I've opened each version of the file and confirmed that it has the complete scan results in it, so I don't know why the server thinks the file is empty.) Unless you have any ideas on what I'm doing wrong here, I'll just try to upload this again later in the morning.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just post it in line (copy & paste) and I'll change it.
     
  13. jcaitlan

    jcaitlan Private E-2

    Edit by chaslang: The file was too large to upload as a text file. ZIP'd it and uploaded it.
     

    Attached Files:

    • bd.zip
      File size:
      26.3 KB
      Views:
      1
    Last edited by a moderator: Sep 9, 2005
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you look in the C:\WINNT\system32\AtapiDrv folder using Windows Explorer, how many files do you see? And what are a few of their names?
     
  15. jcaitlan

    jcaitlan Private E-2

    Here's all the subdirectories and files in winnt\system32\atapidrv:

    logs (subdir)
    no files

    rec (subdir)
    keep.this.file (0 kb)

    sounds (subdir)
    no files

    aliases.ini
    cs.dat
    mirc.ini
    n.dat
    s.dat
    udp.dat
    wserver.exe.xxx
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm actually leaning towards deleting all those folders and files manually. I'm just wondering why BitDefender and RAV are not doing that themselves. Did you run them in safe mode?

    I still wonder where all those items came from and what they are for. You could trying looking at some off the files (like the .ini and .bat files) with notepad or wordpad to see what it in them. Just make sure you do not double click on any of the file because that will make them run (if they are executable). Right click on them and choose Open with and then select Wordpad .
     
  17. jcaitlan

    jcaitlan Private E-2

    I ran both RAV and Bitdefender is Safe mode last week and today. Ya got me why they're not finding and deleting the infected files. Heck, I'm curious why Norton AV didn't do that two years ago....

    Here's what I'm seeing in the ini and bat files:

    aliases.ini
    "[aliases]"

    mirc.ini
    Looks legit. Lists different types of sound files and setting options. Let me know if you want to send you the contents.

    Opened that strange little "keep.this.file" file in recv folder, but it was empty.

    I'm open to deleting the infected folders and files as well. Just want to do it incrementally, and be sure we can recover in the event any of these cause us a headache.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is in the share.bat file?

    If you have someplace you can back them up to (like CD writer etc) that would possibly be a good thing to do first. While many of these file names do get hits as being malware related, not all of them do. I'm not really convinced yet that they are really problems.

    Another thing you could try is just renaming the AtapiDrv folder to something else (like AtapiDrv-backup) and then reboot your PC and see if it works OK. This will not change anything with BitDefender. I just want to see if your system needs these files for something.

    Also is that bc.exe.xxx (as you renamed it) a file. Or is it a folder!
     
  19. jcaitlan

    jcaitlan Private E-2

    bc.exe is a file; not a folder.

    What's the path name of the share.bat file, and I'll check it out and get back to you.

    I have no problem backing up the atapidrv director, renaming the folder, and then rebooting to see what the impact is. I'll do that and let you know how it goes.

    Thanks again for taking time to help me out on this.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But the file is not bc.exe anymore is it?

    The share.bat file is in the AtapiDrv folder according to your log. That's c:\windows\system32\AtapiDrv
     
  21. jcaitlan

    jcaitlan Private E-2

    No, i renamed the file "bc.exe.xxx" as you requested earlier.

    I re-verified that there is currently no "share.bat" file in the C:\WINNT\system32\AtapiDrv director.

    Perhaps it was deleted by one of the BitDefender scans we re-ran last week. I did a search of the system drive for "share.bat" and found no match.

    I renamed the C:\WINNT\system32\AtapiDrv as "C:\WINNT\system32\AtapiDrv.xxx" and rebooted. No problems noted on boot, and no problems associated with any of the drives so far.
     
  22. jcaitlan

    jcaitlan Private E-2

    After renaming the AtapiDrv folder, I used the PC for a couple of hours with no apparent problems.

    Couldn't establish a network connection at first, but after running virus scans (Norton AV, Trojan Remover, Bitdefender) the connection worked. (This is the typical pattern, so no change there.)

    Is it time to backup the AtapiDrv folder to CD, and delete this sucker?
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that is what I would suggest.

    Also backup and delete the below files (if they still exist):

    C:\WINNT\system32\bc.exe.xxx
    C:\WINNT\system32\drivers\savenow.exe
    C:\WINNT\system32\Libparse.exe
    C:\WINNT\system32\zx\Libparse.exe <-- for this one I question the whole zx folder
     
    Last edited: Sep 12, 2005
  24. jcaitlan

    jcaitlan Private E-2

    Backed up the following files/folders:

    C:\WINNT\system32\AtapiDrv\ (all files, including wserver.exe.xxx)
    C:\WINNT\system32\bc.exe.xxx
    C:\WINNT\system32\drivers\savenow.exe
    C:\WINNT\system32\Libparse.exe
    C:\WINNT\system32\zx\Libparse.exe <-- for this one I question the whole zx folder

    The "wserver.exe" file appeared in one additional location and I backed that up and deleted it as well.

    C:\Drivers\wserver.exe.xxx

    I also emptied the Recycle Bin before rebooting.

    Rescanned using BitDefender 8. No infected files found.

    I'll run the PC thru its paces this afternoon to see how it acts, and get back to you with the results.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  26. jcaitlan

    jcaitlan Private E-2

    Many thanks, Chaslang. I've run the PC for 2 days with no indication of any problems connecting to the Internet, and no indication of spyware or viruses.

    I started using almost all of the recommendations on the Malware checklist last year (after this laptop had been infected by the trojans), so I would hope we're in pretty good shape from here on out.

    I use Norton AV and Firewall, as well as Systemworks to clean up temp files. I run Ad-Aware, Spybot S&D, and Microsoft Antispyware weekly. My IE settings were already at the level you recommended. I've been using Firefox since last November, and update as each release is announced. I'd had uninstalled MSFT java and installed Sun Java as well.

    Thanks again for walking me thru the Trojan id and removal process. It's easy to know what files to delete; not always easy to know which ones not to.

    Best of luck and let me know if I can ever be of help.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds