Help with Backdoor.Graybird.GEN & Backdoor.Rbot.avm

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by WakeDL, Aug 14, 2006.

  1. WakeDL

    WakeDL Private E-2

    I have completed everything in the Read & Run Me First.... - TWICE, lol

    I just turned off sys Restore before rebooting for 2nd safe mode scan.

    I've included all my text files from scans except one. Panda ActiveScan didn't find anything but that was after it had been removed by spyware doctor (it came back though)

    Detected on my PC:

    Backdoor.Graybird.GEN
    Backdoor.Rbot.avm
    Downloader.agent.arh
    Riskware.Risktool.win32.processor.20

    I have tried spyware doctor, ewido adaware, WindowsDefender, a2 free, spybot sd, and the online scans; but Backdoor.Graybird.GEN comes back.

    Dell Dimension 8200
    2.53 gigahertz Intel Pentium 4, 8, 512
    80 gig hd

    From System Properties under My Computer
    Windows XP Home Edition Service Pack 2 (build 2600)
    1.5 GB of RAM

    Please help, I can't get rid of this thing on my own. I've even tried rebooting into safe mode 4 straight times removing it a couple times but it still comes back.

    Thanks,

    Dave
     
  2. WakeDL

    WakeDL Private E-2

    BitDefender scan
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    In order to properly say you have completed the READ & RUN ME, the below logs must all be attach here:

    runkeys.txt - the log from GetRunKey.bat
    newfiles.txt - the log from ShowNew.bat
    CounterSpy - ONLY IF you were not able to run Windows Defender
    Bitdefender - from step 6
    Panda Scan - from step 6
    HijackThis
     
  4. WakeDL

    WakeDL Private E-2

    OK, attaching files.

    Windows Defender ran with no problem so I didn't run CounterSpy.

    Thanks for helping,

    WakeDL
     

    Attached Files:

  5. WakeDL

    WakeDL Private E-2

    Panda didn't find anything but I'm reattaching BitDefender report also.

    WakeDL

    I've also scanned several times in safe mode with vcleaner and f-bot.

    I also just had to repair my OS cuz it crashed some of my system files.

    WakeDL
     
    Last edited: Aug 15, 2006
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why were the below running when you ran HijackThis?
    C:\Downloads\RootkitRevealer\RootkitRevealer.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\WINDOWS\system32\taskmgr.exe

    Also you had at least three browsers running. Didn't you read the instructions in step 7 of the READ ME? None of these should be running when using HijackThis.

    Are your copies of Ewido and Spyware Doctor free trials or paid versions?

    Now let's beginning the fixing!

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to APVQUS ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    APVQUS

    If you receive any error messages just ignore them and continue.

    Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\DOCUME~1\David\LOCALS~1\Temp\APVQUS.exe
    C:\DOCUME~1\David\LOCALS~1\Temp\Temporary Directory 1 for ClnNetsky[1].zip\ClnNetsky.com

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O4 - HKLM\..\Run: [0255461155574830mcinstcleanup] C:\DOCUME~1\David\LOCALS~1\Temp\0255461155574830mcinst.exe C:\PROGRA~1\COMMON~1\McAfee\Installer\cleanup.ini -cleanup -nolog
    O15 - Trusted Zone: http://download.windowsupdate.com

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\Common Files\McAfee <--- the whole folder
    C:\Documents and Settings\David\Local Settings\TEMP\APVQUS.exe

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Documents and Settings\David\Local Settings\TEMP
    C:\WINDOWS\Temp\

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Aug 16, 2006
  7. WakeDL

    WakeDL Private E-2

    Hi,

    I followed the previous instructions and the PC got worse over the next week or two. It became more and more unstable and the CPU would pin to 100% and be virtually worthless.

    I finally broke down and did a full re-format and clean re-install. I've tried to limit putting old files back on, but had to put some back on.

    Attached are the new log files and HJT.

    Since the full re-install:

    ZoneAlarm found win32.yok

    RemoveIT found something like patch 32 or win 32 patch
    I selected "fix" but it didn't list it in a log file and it's not in the Quarantine list - sorry - I clicked to fast.

    Also something is un-installing:
    SpybotSD.exe
    RemoveIT Pro XT2 - SE
    (and maybe) Adobe Flash Player


    1) "Why were the below running when you ran HijackThis?
    I close all prior to selecting "fix" but that time I think I was just getting a log file to provide.

    2) "Are your copies of Ewido and Spyware Doctor free trials or paid versions?"
    Spyware Doctor is paid, Ewido is 30 day free.

    Thanks for all the help!

    WakeDL
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should have come back and finished up the thread. We were not done and you did not post any follow up as requested in my last message.

    Uninstall the free trial of Ewido also uninstall Windows Defender since you have a paid version of Spyware Doctor. In addtion, I would recommend uninstalling Advanced WindowsCare V2 Beta 3.62 to avoid additional conflicts with Spyware Doctor and excess use of system resources.

    The logs that you posted do not show any malware problems.
     
    Last edited: Sep 7, 2006
  9. WakeDL

    WakeDL Private E-2

    "Uninstall the free trial of Ewido also uninstall Windows Defender since you have a paid version of Spyware Doctor"

    OK, done!

    "You should have come back and finished up the thread. We were not done and you did not post any follow up as requested in my last message."

    Yeah, sorry PC was a major prob. Should I start over and repost?

    WakeDL

    P.S. I have this ctfmon.exe process that I don't like at all.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And what about Advanced WindowsCare?


    Why would you need to post? You don't appear to have any malware problems. And that includes ctfmon.exe which is a valid process and is part of MS Office.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds