Win.32.backdooragent

Discussion in 'Malware Help (A Specialist Will Reply)' started by mdd, Jan 7, 2008.

  1. mdd

    mdd Private E-2

    I'm not entirely sure how I became infected with something so damn frustrating (as I usually keep myself rather safe) but I have. I've done pretty much everything suggested in terms of cleaning the drive but the computer is still not 100%. I'm not a particularly technical person so, while I've complete the ComboFix, AV & MG scans-- I'm not entirely sure where to go from here. Any help in ridding my PC of this scurge would be most appreciated!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Three possiblities based on a quick look at your logs.
    1. Not keeping all of your software up to date is an invitation for malware to sneak in via any security wholes. A few quick examples of things I can easily see that are out of date:
      • J2SE Runtime Environment 5.0 Update 6 <-- way out of date and a security risk
      • Mozilla Firefox (2.0.0.6)
      • Spybot - Search & Destroy 1.4 <-- this is the least problem of the 3 since it is still somewhat supported but the current version is 1.5 as given in the READ & RUN ME.
      • Do you have all of your Windows Updates installed???
    2. Even a bigger problem that above is the fact that you are running multiple antivirus programs and the first steps in the READ & RUN ME even specified you should not do this. It causes conflicts and does not improve your security. It actually lowers your security because each program becomes less effective. It can also cause permanent problems to Windows Security Ceneter. Either uninstall Norton or uninstall Avira now! You choice but one must go immediately before you continue.
    3. Using programs like BitTorrent DNA is one of the biggest reasons why people are in forums like this looking for malware removal help.
    4. Your Desktop is cluttered up with dozens of unnecessary files (JPGs, ZIPs and more) You should either delete these or move them someplace else if you need all of these. Malware loves to take advantage of cluttered Desktops.
    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    Mozilla Firefox (2.0.0.6)

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  3. mdd

    mdd Private E-2

    Thank you so much for your assistance and sage advice. I have taken into account everything you have said and I've deleted the programs you suggested, as well as cleaned everything up a great deal. The computer seems to be functioning properly once more but I've attached the MGLogs.zip just to be sure.

    I appreciate the time and effort you've taken to help me solve this problem-- thank you kindly.
     

    Attached Files:

    Last edited: Jan 8, 2008
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run Avenger as requested? Please attach the requested log. Your HJT log still shows the same infection line which is:

    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,

    Did you miss this line? Try fixing it again and attach a new MGlogs.zip file.
     
  5. mdd

    mdd Private E-2

    I have run Avenger no less than four times and each time it tells me that "C:\WINDOWS\system32\ntos.exe" cannot be found.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but you never attached the log that it would produce as I requested. Also you did not answer my question about fixing the F2 line with HijackThis. Did you fix it now? Did it come back? Attach the new MGlogs.zip file as requested in message # 4.
     
  7. mdd

    mdd Private E-2

    I've re-run both Avenger and HJT as requested. Logs are attached. I believe I have completed these tasks as per instruction, I had fixed the F2 line in HijackThis earlier but it returned. After doing this task again however, it appears not to have returned.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    12. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds