trojan horse BackDoor.HupigonXTA (help)

Discussion in 'Malware Help (A Specialist Will Reply)' started by jwb38sbcglobal, Aug 5, 2007.

  1. jwb38sbcglobal

    jwb38sbcglobal Private First Class

    hi i did a windows update, and when it was installing, my virus program(AVG free edition )found a trojan{trojan horse BackDoor.HupigonXTA}Path :C:\WINDOWS\system 32\dllcache\tcip.sys,and then it found another one {trojan horse BackDoor.HupigonXTA} Path :C:\WINDOWS\system 32\drivers\tcip.sys i healed both of these and it sent them too the virus vault,i always delete anything from the virus vault,big mistake!!when i restarted the pc after the update and it finding that stuff, and then removing it i couldnt connect to the internet ....i looked and looked for a fix ,system restore wouldnt work ,i ended up getting it fixed by going to the network connections and right clicking on the eithernet conection and going to proptries and then highlighting the internet protocols (tcip\ip)and clicking install ,then tryed to connect and it worked ,,,(i think this is what fixed it)....then when i got up this morning the virus program had found them agian and they were in the vault and so i restore them from there and got back online ,how can i fix this and get rid of them .....and this was from windows update, i dont get that at all i trust them update and now this ??

    any help would be great thanks for your time jwb38

    wasnt sure if this should go in the networking or software section ....sorry
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. jwb38sbcglobal

    jwb38sbcglobal Private First Class

    ive been running counterspy in safe mode for about 10 hrs now and its not even half way done,was wondering if this is normal?for it to take so long,i have a 160 gb hd ,then a slave 160 gb hd and also a 160 gb external hd also ,its still on the c drive so it will take days for it too finish im guessing..im send this with my laptop.....incase u were wondering if the pc im fixng is online now it isnt....thanks for your help....jwb38


    it has found 2 files so far (there r trojan. fakealert trojan)2 objects
     
  4. jwb38sbcglobal

    jwb38sbcglobal Private First Class

    since asking about the time for counterspy too run ive turned off the extra hd .so it wont have too check that one ,i hope by turning it off while it was running and in safe mode it wont hurt anything,i did not get any error messages when shutting it down so i think it should be ok ...just wanted to inform u of this action i took ...thanks
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do as much as you can and attach the logs .....Counterspy can take a while depending on the size of the drives and the number of files it has to scan. Hopefully you followed the instructions and deleted temp files and removed unwanted programs.
     
  6. jwb38sbcglobal

    jwb38sbcglobal Private First Class

    well i just spent hrs with Bitdefender and at the end it closed ie ,so i guess ill go on and do the panda run ,it found some stuff in the system restore ,but i knew that it was in there and needed to get rid of it (trojan horse BackDoor.HupigonXTA)3 files ....and i didnt save the counterspy log becasue it didnt work right and i didnt see the save file,it did let me get rid of the stuff with counterspy ....so i dont know i hope that it will let me save the panda scan ,and then ill do the two other runs GetRunKey &
    ShowNew and the hijack and then post ...thanks jwb38
    ill check back soon before the panda is done and see what u guys say ,well it just shut ie down again so ill restart the pc and run the last steps and wait to here back from someone if i dont then ill send the logs from GetRunKey &
    ShowNew and the hijack thanks jwb38
     
  7. jwb38sbcglobal

    jwb38sbcglobal Private First Class

    ok ,well heres the logs from the 3 that i could get, GetRunKey &
    ShowNew and the hijack this ....ill be waiting to hear from someone ..thanks jwb38
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  9. jwb38sbcglobal

    jwb38sbcglobal Private First Class

    heres the scan from Bitdefender,and the scans from virustotal,there were 2 files one is the orgianial file and the other is a copy im guessing ,panda shut down on me so i dont have that scan,,thanks for your help
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They are both exactly the same according to your logs! And neither of them is infected. Also notice one of the scanners is a version of AVG and it found nothing wrong.


    You need to delete the below file and make sure that Kazaa is not downloaded or installed on this PC anymore:
    C:\Documents and Settings\Compaq_Owner\My Documents\Downloaded Programs\kmd202_en.exe


    You also need to uninstall the 6 old versions of Sun Java you have installed as requested in step 6 of the READ ME. Only Java(TM) 6 Update 2 should be installed.
     
  11. jwb38sbcglobal

    jwb38sbcglobal Private First Class

    ok i tossed the kmd_202,it wasnt on the pc ,just a install file ...removed the java stuff and removed all the stuff in the avg virus vault,im guessing it ran last night and didnt find anything,and i was still online this morning so im guessing everything is alright ...i toggled the system restore off and then back on..there was some system restore files that were in the virus vault that had the trojan ,along with the tcip/ip files ,i tossed all this stuff ,will i be able to do a system restores again ,if so not just them restore points for that day?thanks for all your help in getting this problem fixed.....jwb38
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure I follow what you are trying to ask about doing a restore. If you toggled System Restore, you have flushed all restore points and you only have the one just created after you re-enabled it.
     
  13. jwb38sbcglobal

    jwb38sbcglobal Private First Class

    ok i got you ,thanks for your help ,so u answered my question about the restore ,there will only be one ,i see ...thanks jwb38
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds