W32/backdoor-CFB virus + others

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by kittee, Sep 27, 2004.

  1. kittee

    kittee Private E-2

    If you are reading this then thankyou. If you can help what is beginning to feel like a desperate situation then many many gratitudes.

    I have tried all the usual and recommended tools to no avail. Apart from a continual stream of cws infections. Including your-search. Stinger has detected a W32/backdoor-CFB virus.My windows media player has taken it upon itself to open up whenever I boot the computer. The whole thing's running at prehistoric speed and applications have taken on a mind of their own, opening, closing and causing my computer to freeze up more and more often.
    Some suspicious processes seem to be running (judged so by an absolute amateur's opinion).

    If this is too much for one thread let me know

    Apart from reinstalling everything , I am at my wits end.
    Thankyou
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't know what this means, "all the usual and recommended tools ". You need to be more specific.
    Did you run ALL the steps in this thread: READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    If so, did they find and clean anything.

    If you have run ALL the above steps, you should read the tutorial in this Sticky thread < Hijack This Tutorial And How To Post Your Log File >

    And post a HijackThis log as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail, items in the tray, anything you can close... Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT

    You said, "Stinger has detected a W32/backdoor-CFB virus" . Did it fix it?
     
  3. kittee

    kittee Private E-2

    Thanks for getting back to me.
    I followed all the steps regarding system restore, safemode, and used adaware, spybot, ccleaner, stinger, cwshredder, and a full system scan with Norton 2002
    \Stinger still detects the W32/backdoor-CFB virus

    The Norton antivirus found 4
    Insecure classload...
    installer.class
    getaccess.class
    dummy.class

    all were quarantined.
    HJT log to follow
     

    Attached Files:

  4. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Try removing these and let us know:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = ,
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = ,
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = ,
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = ,
    R3 - URLSearchHook: MailTo Class - {FDE3577A-6254-181C-4E11-339E4F746BD3} - C:\WINDOWS\System32\wins32t.dll

    What are these?
    O4 - HKLM\..\Run: [Hacker Eliminator] C:\Program Files\Hacker Eliminator\HackerEliminator.exe
    O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\SpyHunter\SpyHunter.exe
    Remove them and stick to the programs we offer for download here :) Uninstall those 2 from add\remove programs.

    O4 - HKCU\..\Run: [System Update] C:\WINDOWS\System\wininet.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = ?
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
     
  5. kittee

    kittee Private E-2

    Thanks,

    I haven't seen any signs of anything problematic yet. The Spyhunter and Hacker Eliminator are other anti-spyware tools I have tried. They don't appear on the add/remove list so I deleted the files from my C: drive. Should I fix them with HJT as well?

    Not much appears now when I scan with HJT, the first line is an 02...
    Is this normal?
    Is having 31 processes running with very little activity normal? I seem to remember there used to be only 20 something? All these infections have probably just made me paranoid!!

    Much obliged.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They should have been in Add/Remove programs but if you already removed the folders then yes have HJT fix any lines referring to those applications.

    What is the O2 line?

    Having 31 process running is not unusual.
     
  7. kittee

    kittee Private E-2

    The first line is no longer 02...
    The HJT scan looks messy again!
    I was going to post it again, but thought I would ask first as the advice says not to send them uninvited.
    CWS shredder does not remove all the variants either, judging by my recent redirections.
    Had a chuckle at the hacker-humour :)
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes, post your log!
     
  9. kittee

    kittee Private E-2

    Things don't seem to be getting much better with the redirections

    Here is the HJT log
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's because you have one of the new forms of about:blank issues (the about:NavigationFailure version). This can be annoying to remove just like the other versions.

    1) Make sure you have viewing of hidden files enable as per the READ ME FIRST tutorial.



    2) Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now and do not open it again until I tell you too (so print these instructions or save them locally):
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    O2 - BHO: (no name) - {CD4388BB-2F8B-4CE6-AABC-A6F21A5691CD} - C:\WINDOWS\System32\hamel.dll
    O18 - Filter: text/html - {0D8B9D78-B7E1-4A64-97A2-C457714D1F42} - C:\WINDOWS\System32\hamel.dll
    O18 - Filter: text/plain - {0D8B9D78-B7E1-4A64-97A2-C457714D1F42} - C:\WINDOWS\System32\hamel.dll

    3) Now use Windows Explorer (right click Start and select Explore) to locate and delete:

    C:\WINDOWS\System32\hamel.dll
    If you have a problem locating or deleting this file, I need to know that. If it will not delete, reboot in safe mode and continue the steps below in safe mode. If it deletes okay continue in normal mode.

    4) Reset Web Settings by clicking Start, Control Panel (for some systems it may be Start, Settings, Control Panel) and select Internet Options. Then click Programs and click the Reset Web Settings button. Then go back to the General tab and set your home page back to what you like (i.e., www.majorgeeks.com). Click Apply. Now click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    5) Now empty your Recycle bin!

    6) Now whether you are in safe mode or normal mode, reboot.

    7) Connect to the internet open your browser then exit your browser

    8) Create a new HijactThis log

    9) RUn your browser again and come back here and tell me how things are working and post your log.

    Additional things we must look after completing the above:
    I don't like the looks of this line with monitor.exe on but I need more info before deciding anything:
    O4 - HKCU\..\Run: [monitor] monitor.exe

    Can you go to Start > Search > enter "monitor.exe" without the quotes. Right click the file and post the file's properties and version info? Also once you know where the file is located, browse here and submit the file for an a single file online antivirus scan at:

    http://www.kaspersky.com/scanforvirus.html

    Let me know what you find out from Properties info and from kaspersky. If you have difficulty finding the file, setup the below options for Windows Search to look for hidden files:
    Click Search and the Select "All files and folders"
    Enter the filename in the "All or part of the file name:" box, so enter monitor.exe
    Now select "More advanced options"
    Make sure the following check boxes are checked:
    - Search system folders
    - Search hidden files and folders
    - Search subfolders
    Then click the Search button.

    Do you have Talisman Shell Switcher installed? The reason I ask is these lines (do not touch these, just answer my question)
    O4 - HKLM\..\Run: [tapisys] C:\WINDOWS\System32\tss.exe
    O4 - HKCU\..\Run: [tapisys] C:\WINDOWS\System32\tss.exe
     
  11. kittee

    kittee Private E-2

    When I scanned with HJT the lines you mentioned with hamel.dll had changed to nlog.dll
    I followed the steps anyway
    In system32 no hamel.dll existed. I rebooted in safe mode and hamel.dll appeared in the recycle bin. I emptied it and continued.
    All appears OK.
    Windows mediaplayer has stopped opening when I log on
    I have never heard of Talisman Shell Switcher
    Here is my new log
     

    Attached Files:

  12. kittee

    kittee Private E-2

    I did not know how to post the properties of a file or find its version info
    Here is a txt printout of the properties
     

    Attached Files:

  13. kittee

    kittee Private E-2

    Kaspersky did not find any viruses on the monitor.exe file
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log looks okay other than the monitor.exe file. I need properties info on it. What did you give me from prefetch?

    I see you got rid of the tss.exe lines too.
     
  15. kittee

    kittee Private E-2

    I never touched the tss lines,
    not sure how to post properties info, if what I sent you was not it. Right-clicked on the file, selected properties and did not know how to save it so I typed it exactly into a text document
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay the tss lines must have been related to the other problems then.

    Yes, properties info is obtained by right click on the file and selecting Properties. Most valid program files have version tab where you can find lots of information by selecting each of the items in the Item name: pane. Take a look at c:\windows\explorer.exe for an example. Then check out the monitor.exe file and tell me what you get for each of the Item Names.

    Yes you need to type it into your message
     
  17. kittee

    kittee Private E-2

    Speaking of explorer.exe Stinger says it is un repairable. Still detects the W/32-CFB backdoor virus.
    The monitor.exe has no version tab. Just a blank summary tab and the information that it is a pf file in the prefetch file and opens with an unknown application. Its full name is MONITOR.EXE-0889ADA8.pf

    Do you know how to stop my media player opening every time I log on. I assume this is the result of some corruption
     
  18. Kodo

    Kodo SNATCHSQUATCH

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Wait a minute! Why are you now telling me Stinger is complaining about explorer.exe being corrupt. Didn't you run Stinger when you first started this thread when following the READ ME tutorial. Or are you saying this is a new corruption. Did you run Stinger from safe mode.

    You need to have HJT fix the line:
    O4 - HKCU\..\Run: [monitor] monitor.exe

    and boot into safe mode and delete the
    monitor.exe file (whereever it is) and also the one in Prefetch.
     
  20. kittee

    kittee Private E-2


    The explorer.exe could not be repaired is the warning that Stinger has always given, as it attempted to fix the W32/backdoor-CFB virus. This has never gone away.

    The only montitor.exe file found is the one in
    prefetch
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I did not know that. Your first message only said "Stinger has detected a W32/backdoor-CFB virus" You did not say what file. Does it give a full path to the file?
    If it is c:\windows\explorer.exe, this is going to be difficult.

    Did you delete the monitor.exe in Prefetch and were you able to get the line in HJT fixed permanently?
     
  22. kittee

    kittee Private E-2

    c/:windows/Explorer.exe cannot be repaired
    This is the exact line from Stinger
    The monitor.exe file has gone though
    Sorry for not putting in where the virus was, only that it was there
     
  23. Kodo

    Kodo SNATCHSQUATCH

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  25. kittee

    kittee Private E-2

    Got caught up the last few days, windows service pack 2 crashed my system
    No operating system. NO fun!
    Tried the symantec file you suggested. It found nothing, and the about:navigation main search bar lines are back in my HJT log
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why did you try to upgrade to SP2? We did not suggest it. It is not a good idea to upgrade to SP2 with any form of malware present on a PC. It can cause problems in the upgrade. What OS are you running now?
     
  27. kittee

    kittee Private E-2

    Was on automatic update and did not think it was a problem.
    Managed to remove SP2, still got XP SP1 as far as I know.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay so post a current HijackThis log attachment and tell me again what problems you have right now.
     
  29. kittee

    kittee Private E-2

    Here is the HJT log, internet explorer is constantly being redirected, Stinger still reports a W32/Backdoor-CFB virus in Explorer.Exe which it says cannot be repaired.
     

    Attached Files:

  30. Kodo

    Kodo SNATCHSQUATCH

    kittee

    do this for me.

    I uploaded a zip attachement with an SP1 explorer.exe and a batch file for you to download RESTORE.ZIP

    Place the batch file onto the root of C:\ such that it's path is C:\restore.bat
    Place MY version of explorer.exe also in the root of C:\ such that its' path is C:\explorer.exe


    now, hit CTRL+SHIFT+ESC and terminate EXPLORER.EXE in the list of processes.
    in the same window , go to file, new task and type C:\restore.bat and hit enter.


    Now go to file ..new task and type Explorer.exe .. load up your AV and rescan your PC.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Cool idea Kodo. I was thinking about having Kittee replace explorer.exe too.
     
  32. Kodo

    Kodo SNATCHSQUATCH

    Kittee.. any luck?
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Kodo,

    Did you notice Kittee also picked up a new problem. An about:blank/about:NavigationFailure
    hijack.

    This was not present earlier.
     
  34. Kodo

    Kodo SNATCHSQUATCH

    no, didn't see that. Wasn't really following the thread closely.

    Hello Kittee? You There?
     
  35. kittee

    kittee Private E-2

    Followed the directions, Stinger still detects the W32/Backdoor-CFB virus and says Explorer.exe is unrepairable
     
  36. Kodo

    Kodo SNATCHSQUATCH

    do me a favor.
    Start up Stinger then hit CTRL+SHIFT+ESC and terminate EXPLORER.EXE in the list of processes.

    Stinger should still be loaded. Now run it and see if it can clean it.
     
  37. kittee

    kittee Private E-2

    With Explorer.Exe terminated, Stinger did not detect any problems, so it didn't fix anything
     
  38. Kodo

    Kodo SNATCHSQUATCH

  39. kittee

    kittee Private E-2

    The online virus scanner did not find anything wrong with Explorer.exe
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Kittee,

    Kodo and I want to confirm whether explorer.exe on your system has truly been modified. Here is what we are thinking about:

    To see if explorer.exe is really getting infected, we want to get an MD5 signature for a known good explorer.exe (the one Kodo gave you in the download link) and also get one for the explorer.exe on your system after Stinger detects a problem. We are wondering if the problem may be that it is not explorer.exe but something loaded by explorer.exe (like a DLL) that is actually the problem but Stinger detects it in explorer.exe.

    So here is what we want you to do:

    Go to the below link and download and install this small and quick MD5 compare tool we can use:
    http://www.download.com/SolidBlue-W...tml?tag=lst-0-1

    I have already determined the MD5 for the original explorer.exe that Kodo gave to you. Its is: a82b28bfc2e4455fe43022a498c0ef0a

    Copy and paste the above MD5 into the Compare box in WinMD5Sum, now where you see the File name box click on the button to the right that has ... within it. Then browse to your current c:\windows\explorer.exe and select it. This will give the MD5 signature for it and automatically do the compare. Tell us whether they compare or not.
     
  41. kittee

    kittee Private E-2

    The MD5 check sums compare
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What version of Stinger have you been using?

    It is now up to version 2.4.3. Get it here: McAfee AVERT Stinger
    And give it a run see if you sill get the same results. Save the report file this time and post it back here.

    It does not make sense that Stinger would only find the problem when the Explorer.exe program was running. Stinger scans the files not memory. And since your MD5 comes out the same as a good explorer.exe, it does not make sense that anything is wrong with yours.
     
  43. kittee

    kittee Private E-2

    Here is the new Stinger report.
    I can only think that I may have compared the wrong files with the MD5 tool.
    I will try following your instructions again
     

    Attached Files:

  44. kittee

    kittee Private E-2

    The explorer.exe still compare
     
  45. Kodo

    Kodo SNATCHSQUATCH

  46. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  47. kittee

    kittee Private E-2

    Must apologise about the time between replies. Got stranded last weekend with a broken down camper and no computer. Things got a bit hectic when I got back.
    The trendmicro tool seems to have sorted the W32-Backdoor problem. Stinger no longer detects anything wrong with Explorer.exe
    Still occasionally getting redirected due to CWS, fixing that as it occurs. Not sure if I should notice any signs of being cured of the W32?
    Would you take a look at my HJT for a check.
    You guys must know an incredible amount to be able to fix so many varied problems.
    Thanks again :)
     
  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's great news Kittee. I'm happy we finally got that fixed. Yes you should post a new log. It's been a while. You should not be getting CWS problems all the time.

    You should take a look at this thread too and see if there is anything in there you have not done: How to Protect yourself from malware!
     
  49. kittee

    kittee Private E-2

    Lots of little annoyances have stopped. Igfx Tray module kept announcing that it had to close - no longer!!! Much appreciated Chaslang and Kodo.
    Here's the log. All good, fingers crossed
     

    Attached Files:

  50. Kodo

    Kodo SNATCHSQUATCH

    one last problem

    see if you can find this file and delete it
    C:\WINDOWS\System32\tss.exe

    then remove these lines from HJT and post a new log


    O4 - HKLM\..\Run: [tapisys] C:\WINDOWS\System32\tss.exe
    O4 - HKCU\..\Run: [tapisys] C:\WINDOWS\System32\tss.exe
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds