trojan Backdoor:Win32/Zonebac.gen!B

Discussion in 'Malware Help (A Specialist Will Reply)' started by jv200720, Nov 14, 2007.

  1. jv200720

    jv200720 Private E-2

    Earlier today i recieved a notice from windows scanner saying it found my pc had a trojan Backdoor:Win32/Zonebac.gen!B but could not delete it. So I decided to look it up and came across this site and followed the instructions found here http://209.85.165.104/search?q=cach...:Win32/Zonebac.gen!B&hl=en&ct=clnk&cd=1&gl=us involving abri helping darthlbis. Following these instructions i went as far as downloading and scanning with ATF-Cleaner but i noticed he wanted to see logs and that's when i figured i might not be out of this mess yet. please help me out with this i don't really know too much about this computer stuff and this computer is used mostly for gaming and bills which i know now ill have to call my bank and credit cards to let them know of the situation =(
     
    Last edited: Nov 14, 2007
  2. jv200720

    jv200720 Private E-2

    here is the Hijack this log. I ran another scan when i got back home today and i noticed that
    "O2 - BHO: IE - {0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2} - C:\Program Files\WinBudget\bin\matrix.dll (file missing)" was back on there even after i deleted it and that whataboutadog.com was back under my trusted sites and i dont know what to do to fix this :(
     
  3. jv200720

    jv200720 Private E-2

    sorry forgot the log
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  5. jv200720

    jv200720 Private E-2

    oh i apologize for posting the log but i will follow those steps and post once those steps are complete
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What log?
     
  7. jv200720

    jv200720 Private E-2

    i posted the log from the hijackthis scan i did and read not to post them until it was necessary. another thing is im running the spyboy search and i cant seem to find the sdhelper function. I didnt install teatimer but selected for the sdhelper to be installed. is it right in front of my face and im just missing it? or could something have happened that it didnt install.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No that I saw?

    It is one of the options during installation. It is also available on the Advanced Mode, Tools, Resident screen. Don't worry about it now. Just continue.
     
  9. jv200720

    jv200720 Private E-2

    when i try to install sun java runtime environment it says the system administrator has set policies to prevent this installation even though im on the admin account. is there a way to fix this problem so i can install this?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just continue on with the other instructions and ignore Sun Java for now.
     
  11. jv200720

    jv200720 Private E-2

    here are the logs
     

    Attached Files:

  12. jv200720

    jv200720 Private E-2

    the other two
     

    Attached Files:

    Last edited: Nov 18, 2007
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay we are finished with the CounterSpy trial now so please uninstall it then continue on to the below.

    Did you forget to uninstall the below in step 0 of the READ ME or does your problem block uninstalling them? Please try to uninstall them:
    Viewpoint Manager (Remove Only)
    Viewpoint Media Player

    Disable Windows Defender's realtime protection to avoid having it get in our way:

    Disable Windows Defender:
    • Open Windows Defender
    • Click Tools
    • Click General Settings
    • Scroll down to Real Time Protection Options
    • Uncheck Turn on Real Time Protection (recommended)
    • Close Windows Defender
    Once your log is clean you can re-enable Windows Defender Real Time Protection.

    Do you use MusicMatch Jukebox? If no, uninstall it.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\bak\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
    O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
    O15 - Trusted Zone: *.whataboutadog.com

    After clicking Fix, exit HJT.

    Download and run FindAWF by noahdfear.
    • Please download FindAWF by noahdfear.
    • Save to your desktop.
    • Double-click the FindAWF icon.
      • If a Security Alert shows, allow the program to run.
    • As instructed, press any key to continue.
    • Use the following option: Press 1 then Enter to scan for bak folders
    • The scan may take a while, please be patient.
    • When done, a text file, Find AWF report is produced.
    • Please attach the Find AWF report in your next post.
     
  14. jv200720

    jv200720 Private E-2

    im having trouble with windows defender...everytime i open it ill fails to load


    EDIT: nevermind i reinstalled it and got it to run...ill post the next log once its done
     
    Last edited: Nov 19, 2007
  15. jv200720

    jv200720 Private E-2

    here the awf log
     

    Attached Files:

    • awf.txt
      File size:
      1.4 KB
      Views:
      7
  16. jv200720

    jv200720 Private E-2

    is that whataboutadog.com supposed to keep coming back to my trusted sites everytime start up my computer?
     
  17. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    No, it's part of your infection. To keep this thread moving along please follow the instructions below...

    First, Please download DelDomains and unzip it to your desktop. Do not run it yet.

    • Find the files from deldomains.zip on your Desktop and RightClick on the deldomains.inf file and select Install.
    Next, we need to run FindAWF again.
    • Double-click the FindAWF icon.
      • If you receive any security alerts and/or warnings please allow the utility to run.
    • As instructed, press any key to continue.
    • Use the following option: Press 2 then Enter to restore files from bak folders
    • A text file opens called: files.txt
    • Click below the line and paste the following list of files to be restored:
    • Next, close and click Yes to save the changes.
    • Once files.txt is saved, FindAWF does the following:
      • It attempts to terminate the process represented by each filename on the list, if running
      • Deletes the rogue file from the parent folder, if present
      • Copies the original file to the parent folder
    • When done with the above, it automatically runs a new scan and opens a new log.
    • Please provide the new FindAWF log in your reply.
     
  18. jv200720

    jv200720 Private E-2

    heres the next awf log
     

    Attached Files:

  19. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt

    Once you complete the above, please attach fresh logs from the below.

    • GetRunKey
    • ShowNew
    • HijackThis
    • FindAWF log (From the end of post 13)
     
  20. jv200720

    jv200720 Private E-2

    new logs
     

    Attached Files:

  21. jv200720

    jv200720 Private E-2

    heres the other
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Back in message # 13 I asked you to uninstall CounterSpy. You did not uninstall it! You need to uninstall it now. Also since Windows Defender seems to be broken, uninstall it now.

    You also have Spyware Doctor 3.5 (very old and out of date) installed. Is it a trial program or a paid program? If trial, uninstall it too.


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 1

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.



    Then attach new logs from ShowNew and HijackThis.
     
  23. jv200720

    jv200720 Private E-2

    here you go
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It appears that you did not uninstall Windows Defender. Is that because it is working properly now?


    Delete the below folder:
    C:\Documents and Settings\Owner\Application Data\Sunbelt Software

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Viewpoint Manager Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.


    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  25. jv200720

    jv200720 Private E-2

    yes windows defender is working properly now however it seems whataboutadog is still on my trusted sites..will that continue to keep showing up or no?
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Disable Windows Defender (if you cannot disable it, uninstall it) then try fixing that O15 line.

    Tell me if that works. You may need to reboot afterwards to be sure whether it is gone or not.
     
  27. jv200720

    jv200720 Private E-2

    didn't work...now doginhispen.com shows up as well in my trusted sites
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay it is possible that you have become reinfected.

    Download and run FindAWF by noahdfear.
    • Please download FindAWF by noahdfear.
    • Save to your desktop.
    • Double-click the FindAWF icon.
      • If a Security Alert shows, allow the program to run.
    • As instructed, press any key to continue.
    • Use the following option: Press 1 then Enter to scan for bak folders
    • The scan may take a while, please be patient.
    • When done, a text file, Find AWF report is produced.
    • Please attach the Find AWF report in your next post.
    Also run this Using MGtools and attach the requested MGlogs.zip file.
     
  29. jv200720

    jv200720 Private E-2

    new logs
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on the logs you really have not become reinfected. Just the O15 lines showed back up. This could be due to Windows Defender. Please uninstall Windows Defender now. You can reinstall it after we get things fixed if you really wish to keep it. Personally I don't recommend it because it is not very effective and can be a resource hog. We will however have to get your PC properly protected since you don't have any antivirus or firewall installed either. We will do this later too.

    After uninstalling Windows Defender. Have HijackThis fix the below two lines:
    O15 - Trusted Zone: *.doginhispen.com
    O15 - Trusted Zone: *.whataboutadog.com

    Then also as a backup, run the Deldomain.inf that was run earlier.

    Then delete ALL files in the below folder:
    C:\Documents and Settings\Owner\Local Settings\Temp

    Note that Windows will stop you from removing a couple from the current date. Just work around those and get all others deleted.



    Now download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds