backdoor hu.pigeon,

Discussion in 'Malware Help (A Specialist Will Reply)' started by emily_wells, Dec 24, 2007.

  1. emily_wells

    emily_wells Private E-2

    I got the backdoor hupigeon. It has taken away my administrative privileges. I called microsoft here which directed me to their support center in India. Microsoft India support helped at the highest support level, ran every possible anti virus software,- trend housecall, smitfraud and afew others. does not let anything to be installed. Says "need admin privileges." Does not even let me do- start-run-msconfig, regedit or even access my clock.

    I can see a new user name installed on my pc.

    In my c:\InstallHelper which was created the day the trojan got in I see the following :
    ------------------------------
    rgv[0] = C:\Program Files\eBay\Turbo Lister2\TLReg.exe, argv[1] = I
    Not Vista.
    Install is called.
    Logon user is xyz
    Adm user name is xyz$.
    Adm Sid is so-and-so
    Adm regKey is so-and-so\Software\eBay\Turbo Lister2.
    RegQueryValueEx get InstallLocation C:\Program Files\eBay\Turbo Lister2\
    RegKey copy for logon user is done.
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Welcome to Majorgeeks!

    See how much of the below you can get through and attach any of the logs you can get...

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. emily_wells

    emily_wells Private E-2

    Hi,

    I did every single step as directed in the document:
    "read and run me first".

    As stated in the above doc I tried, combofix (had tried that before with MS help desk in India), spybot, Avganti spyware, CCleaner. All the attempts end with, " need admin privileges".
    This is the answer I get for any thing I try to run or install.

    I could not auto finish "MGTools".
    It says "For some reason your system denied write access to the hosts file. If any hijacked domain are in the file, hijack this may not be able to fix this....."

    I tried manually to run all the bat files in c:\MGtools.

    It did not finish for me to create the "MGlogs.zip".
    There are other files like "hijackthis.log".
    Would you like me to send that to you ?

    Thnx.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What Windows OS are you running?

    If you look in the C:\MGtools folder, which of the below log files do you see (attach the ones you do see):
    • GetUnKey.txt
    • hijackthis.log
    • newfiles.txt
    • runkeys.txt
    • procdll.txt
    See this: HOW TO: Attach Items To Your Post
     
  5. emily_wells

    emily_wells Private E-2

    My OS is xp pro. Service pack 2.

    Except procdll.txt I have rest of the files.
    When I run the processDll.exe it says "app failed to initialize".
     

    Attached Files:

  6. emily_wells

    emily_wells Private E-2

    Here are more attachments.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Know wonder you are having problems with the tools. You are badly infected.
    Do you know what the below three items are for?
    O4 - HKLM\..\Run: [LAAM] c:\agilent\bin\runit c:\Agilent\bin\s_user.exe
    O4 - HKLM\..\Run: [adcius.exe] c:\Agilent\adci\adcius.exe
    O4 - HKCU\..\Run: [adcist.exe] c:\agilent\adci\adcist.exe

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now we need to stop and disable a bad service.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to WindowsService
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [waumgr] waumgr.exe
    O4 - HKLM\..\Run: [AutomaticUpdates] AutomaticUpdates.exe
    O4 - HKLM\..\Run: [csrss] C:\RECYCLER\S-1-5-21-484763869-1614574334-18083462561-100\run.bat
    O4 - HKLM\..\Run: [svchost] C:\RECYCLER\S-1-5-21-484763869-1614574334-18083462561-100\svchost.exe
    O4 - HKLM\..\RunServices: [waumgr] waumgr.exe
    O4 - HKLM\..\RunServices: [AutomaticUpdates] AutomaticUpdates.exe

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\spittal\Local Settings\Temp\

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created (hopefully it works okay now) by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  8. emily_wells

    emily_wells Private E-2

    hi,
    while waiting for your reply I started trying other things. Due to the virus I had very limited privileges on my machine and was unable to execute most of the virus removal sw. I was trying to get back control of my admin rights and hence used a 'ERD commander' utility that lets you reset your passwords. My computer was set up for work domain. Using the utility I changed the password, now I cannot log on to my PC at all, none of the passwords for either users or admin work. The only things I can do is boot the pc thru the 'erd' cd. i do not have any internet browser on it yet. i need to figure that one out, right now I am using another laptop.

    I need to log into windows. I am told 'erd' did not work cause the way pc was set up to log on to the machine itself plus to the work domain. now I am no longer connected to or access the work domain, but the change password did not work and messed up the old passwd too. Can't log in to my machine at all.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well I cannot really help you in the Malware Forum with this new problem you have created. I will suggest you take look a make and using a CD as mentioned in the below to reset the passwords to blank.

    http://home.eunet.no/~pnordahl/ntpasswd/

    Other than that, you will have to look for help in the Software Forum for your current issue of not being able to log in.
     
  10. emily_wells

    emily_wells Private E-2

    I already had this (http://home.eunet.no/~pnordahl/ntpasswd/) burnt down on a CD and has been using this along with the ERD commander, none of them work.

    How do I move my thread to sowtware now ?
    Thank you for all your time and efforts.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The NTPassword reset works just fine if you understand everything to select while it loads up. Also you must not try to create a new password. Just use the option to blank out any existing password.

    You would have to create a new thread for your current problem. That way once you get it fixed you can come back to this one that already has malware fixes in it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds