"notepad.exe" infected with Trojan.Banbra.Hb

Discussion in 'Malware Help (A Specialist Will Reply)' started by sweetTart, Jul 20, 2008.

  1. sweetTart

    sweetTart Private E-2

    Yesterday while using the internet my computer slowed way down, so I opened Task Mgr to see what was running. There was four instances of 'notepad.exe' running in Processes, and I wasn't using notepad at all. So I tried ending the processes, but one kept popping right back up. I uploaded the file to jotti and the scan result from ArcaVir said 'notepad.exe' was infected with 'Trojan.Spy.Banbra.Hb'. Also, a few days ago I tried to run Kaspersky online scanner but it froze during the scan. The scan window said it had found 5 infected files and 6 security errors, but there wasn't a button for me to push to view the log file. It also seems like my Windows files are being replaced with files for different versions of Windows. I followed the steps in Read & Run Me First and I am attaching the files. Thanks in advance for your help!
     

    Attached Files:

  2. sweetTart

    sweetTart Private E-2

    Here is my Combofix log and MGTools log. Thanks again.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Your logs do not show any remaining malware issues. A few things were fixed by the scans and perhaps they have resolved your issues. The current notepad file you have appears to be the correct file size.

    I do have a little for you to do.

    First we need to cleanup some items from running ComboFix.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Are you still having problems? If not then do the below final instructions. If you are having problems, describe them in detail.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the combo-fix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combo-fix folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  4. sweetTart

    sweetTart Private E-2

    Hi chaslang, thank you for your help! I did get a message saying that the registry merge was successful. But I have a couple of question because I'm confused. I re-submitted the notepad.exe file to jotti and it still comes back positive. Do you think it's a false positive? Also, I use Zone Alarm firewall, and it tells me that I don't have any antivirus software installed on my computer, and I have Avast. Lastly, I keep getting references to my browser being 'netscape navigator'. I use Firefox or IE, and have no idea how netscape got here. When I open my browser and type in a web address, I use TCPView and immediately I have 5 different http connections, one is always https, all with different remote addresses. Could this mean that malware or something is using the internet connection when I am to send information somewhere? I hope I'm not getting too off track, but it all seems suspicious to me. What do you think?

    p.s. I haven't done anything yet but the registry merge.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Where is the file located? Is it the one in C:\Windows\System32 or is it in C:\Windows or is it somewhere else?

    Do the following: Click Start, Run and enter sfc /scannow into the Run box and click OK. There is a space after the sfc. This may ask for your Windows CD so have it ready. Let me know if it does ask for the CD. Afterwards reboot and let me know if still having issues with notepad. It is possible that like your svchost.exe file that notepad has gotten an ADS infection (that is Alternate Data Stream). It is also possible that your svchost.exe file is still infected and that ComboFix did not fix it as implied. This could mean others also got the infection. Even though files sizes may look normal, an ADS infection could still be there. That is the nature of ADS.

    It could be an issue with ZoneAlarm just not properly detecting it or it could be due to having other antivirus programs installed at some point. What else have you had installed.

    Can you be more specific. Do you mean something is saying that your default browser is NetScape? If so, just set FireFox or IE back to being your default.

    Again please be more specific, what connections/addresses are you seeing and which browser does it occur with.
     
  6. sweetTart

    sweetTart Private E-2

    It's in C:\Windows\System32. I don't have a Windows CD, my computer came with Windows XP pre-installed with no operating system disks. Should I still do the sfc /scannow?

    Norton Internet Security came pre-installed, but I uninstalled it. I tried AVG (the free one) but the updates would never install so I got rid of it and replaced it with the Avast.

    I visited a site called DNSStuff.com, which told me about Netscape. Also in my registry under "HKCU\Software\Netscape\Netscape Navigator\User Trusted External Applications" there are 4 different keys for wmplayer.exe, 1 javaws.exe, 1 RealPlay.exe, and 1 AcroRd32.exe. It's also listed under "HKU\.DEFAULT\Software\"

    Does this mean anything or am I just being paranoid?

    Ok for instance I had this browser window open in IE as I'm typing this so I saved the TCPView file for you to look at (so I attached it to this post)


    I hope I'm not being a pain, but I really do appreciate your help.
     

    Attached Files:

  7. sweetTart

    sweetTart Private E-2

    Also, chaslang, there is now a new folder on my C:\ drive called "QooBox". I haven't opened it because I don't know what it is or where it came from.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run it anyway and see if it asks for the CD.

    The latter. ;)


    Looks quite normal.


    The QooBox folder is the backups/quaratine folder for ComboFix.

    You may have ADS infections in multiple system files. This is why I wanted to run sfc /scannow to see if it could repair them.

    Please also run the below and attach the log:

    Using SDFix
     
  9. sweetTart

    sweetTart Private E-2

    Ok, I ran sfc /scannow and it asked me to insert my 'Windows XP Home Edition' cd 13 times, and my 'Windows XP Home Edition SP2' cd 22 times. I'm going to do the SDFix now, I will post the results when finished.
     
  10. sweetTart

    sweetTart Private E-2

    Here is the log from SDFix
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to get a copy of Windows XP Home Edition SP2 on CD. Even if you have to borrow one from some one to run the fix. We cannot help you any further since you have bunch of Windows files that are corrupt, or missing or infected. Since we also don't know which files they are, it makes it even more difficult. I do know that your svchost.exe file was or still is infected and needs to be replaced with an uninfected copy. The sfc command maybe be able to cure all of the ADS infections. Running any other tools to attempt to find and repair the ADS infections in system files could potentially lead to your system becoming unbootable.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds