Backdoor.haxdoor.c won't go away

Discussion in 'Malware Help (A Specialist Will Reply)' started by Sandytech, Jun 5, 2006.

  1. Sandytech

    Sandytech Private E-2

    I have gotten the message that this virus has infected winm32.dll in the system32 directory under windows. This virus will not allow me to start any program in normal mode. My Norton was up to date (as of June 1) and a full system scan was run June 1 with no viruses found. AdAware was also run June 1 with any malware removed. I have followed direction on the sticky for removing the malware but have not gotten anywhere. I can start in Safe mode and run Norton but it still finds nothing. I downloaded Hijack this from your site onto a laptop, copied it to a removable drive and installed it on the infected system as you described into its own folder in Safe mode and ran it. I was able to copy the resulting log onto the removable drive. I don't know where to go from here. I haven't found anyof the other posts that have had this virus prevent all other programs from starting so there wasn't a solution that worked so far. HELP.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See if you can do the below some how even if you have to download the file to another PC and then copy to the problem PC. If you cannot extract it from the ZIP on the problem PC, extract it from the ZIP before copying to the PC.

    Download: HSFix.zip

    Extract the tool from the ZIP File to a folder you can easily find (preferably in its own folder - like C:\HSFix).

    Now please boot to Safe Mode and DoubleClick hsfix.bat to run the tool.

    Allow it as long as it takes to run, then Reboot to Normal Windows and look for a log at C:\hslog.txt . Please attach that log when you come back. Also tell me if things are working any better.
     
  3. Sandytech

    Sandytech Private E-2

    I forgot to mention in my initial plea for help that I am running a Pentium 4 3 GHz system with 500 MB RAM with XP SP2. I uninstalled and reinstalled SP2 2 weeks ago to fix a problem I was having with a print spooler. All Windows and Norton updates are automatic and current - at least until a few days ago when everything stopped.

    OK - now to respond to you suggestions. I did as you suggested. The HSlog as well as the HijackThis logs are attached.

    I rebooted to normal mode and still get the same errors and can't start anything.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of winm32.dll once and then click the kill button. After you have killed all of the winm32.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of winm32.dll and kill it. (If you do not find the dll, just continue on.)


    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: Creata Mail - {9FEA5BDA-695A-417B-AA31-B54A06570053} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - (no file)
    O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralInitialSetup1.0.0.8.cab
    O20 - Winlogon Notify: directpt - directpt.dll (file missing)
    O20 - Winlogon Notify: winm32 - C:\WINDOWS\SYSTEM32\winm32.dll


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.
    C:\WINDOWS\system32\w32tm.exe
    C:\WINDOWS\system32\directpt.dll
    C:\WINDOWS\SYSTEM32\winm32.dll

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.


    Now attach a new HJT log and tell me how the steps went.
    Make sure you tell me how things are working now!
     
  5. Sandytech

    Sandytech Private E-2

    I think I'm toast. I can't do anything in Normal mode. I tried Ctl Alt Del to end processes and it just hangs and gives the virus message (C:\Windows\System32\Winm32.dll is infected). I tried to run msconfig to change the start processes and it just hangs. I copied Process Explorer to the desktop and tried to run it and it just hangs. I also tried running it from the removable drive with the same results. Can any of this be done in Safe mode?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try running the whole procedure in safe mode and we will see.

    Make sure the account you run on in safe mode is the same account you are trying to use in normal boot mode.
     
  7. Sandytech

    Sandytech Private E-2

    I think you did it. I ran everything in Safe mode and restarted into Normal and NO INFECTED FILES!! Just to be sure I re-ran everything that I ran in Safe mode in Normal mode - in case there was something that wouldn't be picked up in Safe mode. I have attached the HijackThis log from after the run. You're AMAZING.:) This was a really persistent virus. Should I now re-boot and enable System Restore? Since I already have Windows Defender, AdAware SE and Norton (and it was up to date and did scan incoming e-mails) what else can I do to prevent a recurrance?
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually, now that your PC is operational again, it would be in your best interest to run ALL steps in READ & RUN ME FIRST Before Asking for Support and then attach the two logs from step 6. I want to make sure everything was fixed.

    The below process is questionable:
    C:\Documents and Settings\Owner\Application Data\U3\0980E950E033B967\LaunchPad.exe

    And the below item should definitely be fixed.
    O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZSXXXXXX47US

    After we are sure all malware is removed, we can then work thru the steps to help keep you better protected.
     
  9. Sandytech

    Sandytech Private E-2

    I have emptied my Norton Protected trash several times and every time there have been threats in there. Also I am running on a secured wireless router and thought that it provided firewall protection. I have also downloaded one of the ones your site recommended as well as AVG to scan all the incoming e-mails since that seemed to be a hot area. I also went to our mail folders and deleted all the messages that were in Junk or Trash
    I followed all the steps and ran the scans, some a couple of times. Attached are the logs for Panda and Hijack this. I got a message that the Bitscan file was too large to upload (504K).
     

    Attached Files:

  10. Sandytech

    Sandytech Private E-2

    I'm re-running BitDefender and will post the log as soon as it finishes. As I look at it when it is running, it shows some viruses in some mail Trash and Junk files but I emptied all of those before I started running the tool so I don't understand where they are coming from. I also emptied my Norton Protected files from Trash before I started and it keeps getting more in there even though no processes other than Bit Defender are running and I am not attached to the server. I guess I'm still in a lot of trouble.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have both Bitdefender and Symantec antivirus applications installed. You must uninstall one of them. See step 3 of the READ ME. Do this now, then continue.

    Please download & run Blacklight Beta
    • Hit I accept. It will take you to download page.
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please attach the Blacklight log file here.
     
  12. Sandytech

    Sandytech Private E-2

    OK - I uninstalled BitDefender and installed and ran Blacklight Beta. Attached is the log.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later to run it.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click OK.

    Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.

    c:\WINDOWS\system32\klogini.dll
    c:\WINDOWS\system32\winm64.sys
    c:\WINDOWS\system32\p3.ini
    c:\windows\system32\klo5.sys
    c:\windows\warnhp.html
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself. However BOOT INTO SAFE MODE during this reboot and do not run anything but what I request. DO NOT open any browsers!

    Run Windows Explorer and double check to make sure the below files are all deleted (some we already got with killbox):

    c:\program files\FlashTalk <--- the whole folder
    c:\program files\MyWebSearch <--- the whole folder
    c:\WINDOWS\system32\klogini.dll
    c:\WINDOWS\system32\winm64.sys
    c:\WINDOWS\system32\p3.ini
    c:\windows\system32\klo5.sys
    c:\windows\warnhp.html

    Also you should find the below items that were in your email folders and delete them:
    C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\paul\Mail\Inbox[~0001139.~]
    C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\paul\Mail\Trash[~0001310.~]
    C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\paul\Mail\Trash[~0003530.~]
    C:\Documents and Settings\Owner\Application Data\Thunderbird\Profiles\juvu2x97.default\Mail\pop-server.nc.rr-3.com\Inbox[~0000175.~]
    C:\Documents and Settings\Owner\Application Data\Thunderbird\Profiles\juvu2x97.default\Mail\pop-server.nc.rr-3.com\Inbox[~0000263.~]
    C:\Documents and Settings\Owner\Application Data\Thunderbird\Profiles\juvu2x97.default\Mail\pop-server.nc.rr-3.com\Junk[~0000016.~]
    C:\Documents and Settings\Owner\Application Data\Thunderbird\Profiles\juvu2x97.default\Mail\pop-server.nc.rr-3.com\Junk[~0000024.~]
    C:\Documents and Settings\Owner\Application Data\Thunderbird\Profiles\juvu2x97.default\Mail\pop-server.nc.rr-3.com\Trash[~0000238.~]
    C:\Documents and Settings\Owner\Application Data\Thunderbird\Profiles\juvu2x97.default\Mail\pop-server.nc.rr-3.com\Trash[~0000278.~]
    C:\Netscape\Users\paul\Mail\Inbox[~0001139.~]
    C:\Netscape\Users\paul\Mail\Trash[~0001310.~]
    C:\Netscape\Users\paul\Mail\Trash[~0003530.~]


    Now reboot into normal mode.

    Now attach a new Blacklight log and a new log from PandaActiveScan and attach them.

    Also tell me how things are working!
     
  14. Sandytech

    Sandytech Private E-2

    I am running the Panda scan now and will send both logs when it finishes. I keep getting virus alerts from Norton that it has detected and removed the virus from the computer and all of them are the backdoor.haxdoor.c and they are all .dll files from C:\Program Files\Norton SystemWorks\ Norton Antivirus\Quarantine\Portal. I have responded to over 100 of these messages all the while that Panda is still running. Is this to be expected?
     
  15. Sandytech

    Sandytech Private E-2

    Here are the 2 logs as you requested. I got over 500 of the messages about backdoor.haxdoor.c but all of the attempts were gotten by Norton and deleted.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    According to your logs, you are clean other than some misc registry entries that Panda provides no specific details on. But these are normally non-problem dormant registry keys.

    You may want to boot into safe mode and run a full system scan with Norton. Save a log and report back what it finds (if anything).
     
  17. Sandytech

    Sandytech Private E-2

    I ran the full scan from Norton in safe mode and it didn't find anything! I just booted up in Normal mode with the internet cable attached and haven't had any invasion attempts. Should I now change the system setting to allow System Restore? I really never thought I would be able to get to this point without reformatting. Thanks!
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  19. Sandytech

    Sandytech Private E-2

    Chasland, I think something else is going on. Between 10:00 this morning and 6:00 tonight I had over 17,000 (17059 to be exact) attempts of backdoor.haxdoor.c to get into the computer. They were all caught by Norton coming in as C:\Program Files\Norton SystemWorks\ Norton Antivirus\Quarantine\Portal\xxxxxxx.dll. Of course I get a message for each attempt that I have to click to clear. Doesn't leave much time for anything else. I disconnected from the internet and ran a full Norton scan and it turned up nothing. I have a secured wireless router, installed one of your suggested firewalls and something is still getting through - even though Norton is catching it. Anything else I can do to prevent these attempts getting though??
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you ever complete ALL of the READ & RUN ME? I don't remember seeing a Bitdefender log. First empty your Norton Quarantine folder and then please do a new scan with Bitdefender and attach the log.

    Also get a new Blackligjht log?

    Did you Disable System Restore, reboot, and then reenable (my instructions in message # 18)?

    Attach a new HJT log too.
     
  21. Sandytech

    Sandytech Private E-2

    I ran BitDefender and it said everything was clean and there was no log. I ran it twice and there was no log to save. I ran Blacklight and it said the same thing and no log was saved on the desktop. Attached is the log from Hijack this. I have not been "attacked" by the messages from Norton, so maybe after the disable system restore, restart and enable it is OK now. Let's hope.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your still clean other than this debateable backweb crap from HP.

    O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe

    See the below to read more about backweb:
    http://www.bleepingcomputer.com/startups/BACKWEB_137903.exe-1975.html

    You can probably just uninstall this. If not, you can simply have HJT fix the above O4 line.
     
  23. Sandytech

    Sandytech Private E-2

    Thanks, Chaslang. I used HiJackThis to fix it and also went into the program file folder where it resided and deleted it there. Everything else seems to be working great :) . No more attacks or frozen programs. In fact, some programs work better than they did before. We had a lot of "unscheduled shutdowns." Thanks again for all your help. I couldn't have done it without you.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds