Potential backdoor trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by thai_american_42, Mar 3, 2007.

  1. thai_american_42

    thai_american_42 Corporal

    I've already followed the READ & RUN ME FIRST. Malware Removal Guide instructions.

    I've been having trouble connecting to Yahoo, and often get the message "Internet Explorer cannot display the web page." A post somewhere else said that this may be a sign of a backdoor trojan at work. Other items: The number lock key on my keyboard comes on and stays on when I boot up. When I close Microsoft Word, I often get an error message that says it must shut down items. My Norton Internet Securit is then shut down and a message come up asking for my permission to send an error message to Microsoft. Also, every now and then, a message come up saying that my computer has detected a new periphrial (?). The only option is gives me is to select "Okay." There is no option to select something else or even to close the window.

    I could not get CounterSpy or PandaActiveScan to work. Attached are hijackthis.log, newfiles.txt, and runkeys.txt.

    Please help!
     

    Attached Files:

    Last edited: Mar 3, 2007
  2. thai_american_42

    thai_american_42 Corporal

    Attached are
    BitDefenderScan-2007-03-03.txt
    and
    AVGAntispywareReport-Scan-20070303-152236.txt
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    More than likely not malware. It is possible that you are blocking access to Yahoo via your firewall, antivirus, or antispyware applications. Perhaps you even mistakenly added it to your Restricted Zone.

    None of these are malware problems. I suggest you post these in the Software or Hardware Forum as appropriate. Consider uninstalling Norton and see if some of you problems (including access to Yahoo) go away. You can reinstall it later if you still want it. It may need a reinstall anyway based on your problem description.

    Possibly because you did not follow the directions in step 6 to uninstall old Sun Java versions and install the current version. The version you are using is at least three years out of date. Let's fix this.

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.1_02
    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
     
  4. thai_american_42

    thai_american_42 Corporal

    Initially, I didn't update my Java because I was unsure whether I needed to remove Java Web Start in addition to that three year old Java version. Also, TD AMERITRADE streamer recommended using that particular three year old Java Version (1.4.1_02) for best results with their product.

    I uninstalled Java 2 Runtime Environment, SE v1.4.1_02, rebooted, and installed the new version as you instructed.

    I rebooted again. I then attempted to use PandaActiveScan panda scan. From the safe mode, I went to http://www.pandasoftware.com/products/activescan?. I then was brought to http://www.pandasoftware.com/activescan/activescan/ascan_2.asp. From the http://www.pandasoftware.com/activescan/activescan/ascan_2.asp page, I enter the country, state, and a valid email (a yahoo account). I then click on FREE Online Scan. Nothing happened except for the appearance of a message in the lower left corner of the screen. The message was a small, yellow triangle with an exclamation point in it. Next to the yellow triangle was the phrase "Error on page."

    From the regular mode, I repeated the same steps at PandaActiveScan. This time, nothing happened. I do not even get the "Error on page" message.

    Some other comments and things that are odd with my computer:
    When I try to open the page http://web2.westlaw.com/signon/default.wl?fn=_top&rs=WLW6.06&rp=/signon/default.wl&vr=2.0&bhcp=1 from Internet Explorer, I get a blank, white page. I can open that page with Mozilla Firefox, however.

    Just before following the followed the READ & RUN ME FIRST. Malware Removal Guide instructions, I deleted Yahoo Tool bar, Yahoo messenger, and a third Yahoo program.

    Please let me know what I should do next.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't have any malware problems showing in your logs! All I can suggest is uninstall Norton (as already suggested) and see what happens. We have seen many people have problems similar to what you are mentioning and Norton was the cause. As I said you may be blocking something yourself due to misconfiguration. Also what is IEPrivacyKeeper doing to you?

    None of this is malware.
     
  6. thai_american_42

    thai_american_42 Corporal

    IE Privacy Keeper ( http://www.browsertools.net/IE-Privacy-Keeper/index.html )automatically cleans up the browser history once I am done surfing the net. I've been using IE Privacy Keeper long before any of the above problems occured and its always been my friend. Could it turn on me?

    The inability to access certain page problems occured and/or got worse once I instealled Internet Explorer 7.0. I've tried disabling and uninstalling Norton and then accessing the noted pages with the same, no access results. It's odd that I can access westlaw.com from Mozilla firefox but not Internet Explorer. I've looked through my Restricted Zone and did not find anything related to westlaw.com or yahoo.com. I've otherwise pursued a misconfiguration theory, but could not find any problem.

    My main malware concern was the message that came up saying that my computer has detected a new periphrial (?) and the only option is gave me was to select "Okay." The screen visual was a little unprofessional and seem something like a backdoor trojan would do to trick me into providing access. (I always rebooted instead of selecting OK) Also, I was concerned about the messages I was asked to send to Microsoft with My Norton Internet Securit shut down due to an error in Micorsoft Word. I thought that some local malware was causing Norton to shut down so that a trojan can complete its access to my computer. I've also had false information showing that Norton Internet Security was working (e.g., icon in lower right of screen) but it in fact was not.

    I feel better now that my logs do not show any malware problem. I do appreciate your help in this matter. Thanks!

    Should I keep AVG installed or, along with Norton, would it be my second anti-spyware running?

    As for removing Norton, I'm somewhat dependent upon it since I don't know what it all does and am unsure what I could use to replace it's (i) Internet Security, (ii) AntiVirus, (iii) AntiSpam features. If you can give me a list and say "these items are just as good as Norton and essentially do what Norton does," I may then be able to finally move away from Norton. Thanks.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Any application could get broken/corrupted and cause problems.

    Disabling is not the same. It must be totally and completely uninstalled. Symantec/Norton software can be just as problematic as malware to remove. Chances are you did not get it all uninstalled. Please attach a ShowNew and a HJT log after you have uninstalled all of Norton and I will verify for you that it is gone.

    I highly doubt it is malware. It may be having a problem loading the proper drivers for some hardware in your system. You should check in Device Manager (under My Computer) to make sure no devices are showing having errors.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds