Backdoor.SDBot.MYX is driving me spare

Discussion in 'Malware Help (A Specialist Will Reply)' started by trollface, Dec 1, 2005.

  1. trollface

    trollface Private E-2

    First and foremost, I've done steps 1-6 in this thread, as well as having tried a few other programmes. The only thing I've not done is turn off System Restore. Why? Because I can't. I go to turn it off and it gives me the warning box about how I'll lose my restore points, but even if I immediately go back to the "System Restore" control panel it's back on. Something seems to have hijacked a couple other of my system tools, too, as CTRL-ALT-DEL does absolutely nothing unless I do it immediately on startup, and EDITREG simply crashes. I've also noticed that my system has really slowed down, even though the Task Manager doesn't seem to say that much of the CPU is being used - I used to be able to play Halo with no slowdown and now it slows down even with no particle effects turned on. And when using FruityLoops a note only sounds about a second after I've pressed the key, which is why this has come to a head today, as I've got a deadline of tomorrow morning to compose two peices of music and send them off, and I can't do it with such a delay.

    I've run Registrar Lite and deleted anything I could find that any website said was connected to Backdoor.SDBot, but nothing seems to work at all. I've done all this a few times, but I've just spent the last 7 1/2 hours trying everything I can possibly find to get rid of this and it's all to no avail.

    So...here is my HijackThis! log, and I hope you can help.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run ALL the steps in the READ ME.

    No online scanners were run and neither was Microsoft Antispyware. Anything else??
     
  3. trollface

    trollface Private E-2

    I've run the Trend Micro online scan (I don't ever use IE) today, and I've installed the Microsoft Antispyware software, run it twice, disabled it to run other scans, and uninstalled it again over the course of today. I've done all the steps you recommend today* and more (such as running Spyware Doctor), often more than once. Nothing has made an iota of difference.

    *Except for disabling System Restore. Because I can't.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    At least two online scans should have been run and I cannot believe they would not find the below trojan.

    C:\Program Files\MsMovies\MsMovies.exe
    O4 - HKLM\..\Run: [MsMovies] C:\Program Files\MsMovies\MsMovies.exe /auto

    Does MsMovies appear in Add/Remove programs?


    Online scanners also leave traces in your log. Did you remove those too? Why???
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If the MSMovies program is not in Add/Remove programs, use the below procedure to remove it.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\Program Files\MsMovies\MsMovies.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [MsMovies] C:\Program Files\MsMovies\MsMovies.exe /auto

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\MsMovies <--- the whole folder

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  6. trollface

    trollface Private E-2

    Except that the thread says:

    I am not using IE, I do not use IE and my IE is not even configured to connect to the internet. So, the best way I can figure it I've followed the rules. If you know of another one that doesn't require IE, then I'll be happy to use it.

    Well, I don't know what to tell you. It didn't. Neither is it listed on the PacMan's Starup List you link to under that section of this thread

    Search one
    Search two

    Now I know it's a Trojan, however, I have deleted it. Thank you.

    No.

    No, but maybe it's because I ran the scans before I downloaded HijackThis!?
     
  7. trollface

    trollface Private E-2

    Okay, thank you, I'm off to do that now, except...

    As I've said, I can't. It makes the noises as if it's going to turn it off, but it doesn't actually turn it off.
     
  8. trollface

    trollface Private E-2

    Okay, so I've now done that.

    Performance-wise, there seem to be a couple of changes, but nothing all that substantial. Booting now seems to take longer than it did, but CTRL-ALT-DEL now works. REGEDIT now closes itself down rather than freezing, and I still can't turn System Restore off. As for the slow performance, no difference whatsoever - there's still about a second between hitting a note on the keyboard and it actually sounding.

    New log posted.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well there is nothing in your HJT log that indicates any problems. Let's dig a little deeper:

    Run this Running Ewido Security Suite and attach the log from Ewido


    Download WinPFind

    Extract it to the root folder of drive C ( C:\ ). This will create a folder called WinPFind in the C:\ folder. Inside c:\WinPFind is a file called WinPFind.exe. Double-click on this file to launch the program. Once it is launched, click on the Start Scan button and wait for it to finish. This program will scan large amounts of files on your computer for known patterns so please be patient while it works as it can take a while, upwards to 30 minutes or more.

    When it is done, it will show the results of the scan. Click on the Copy to Clipboard button and then paste the contents of the log in your clipboard. Then save it to a file using notepad and upload the text file here as an attachment.
     
  10. trollface

    trollface Private E-2

    Okay, done.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may have a few items left around from an old Look2Me infection. Please run the steps in the below link:

    Look2Me VX2 Removal

    The below all showed in your WinPfind log and are not valid. There should be EXE files with the same base filename (base filename means regedit for example). So there should be a regedit.exe. Look to see if all the EXE files exist and what there file sizes are.
    Afterwards post a new log from WinPfind.
     
  12. trollface

    trollface Private E-2

    Okay, I've done that.

    Of the files I should have, regedt, taskkill and tasklist are missing. The others are as follows:

     

    Attached Files:

  13. trollface

    trollface Private E-2

    The other log.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did your PC come preinstalled with WinXP SP2 or did you upgrade to it?
    Do you have a WinXP SP2 CD?

    Also check to see if the following folder is on your PC:
    C:\WINDOWS\ServicePackFiles\i386
     
  15. trollface

    trollface Private E-2

    This computer came with this OS installed, but I do have the CD. That said, though, originally the computer came with a drive missing - with only what is now my D: drive, so I had to have the company send me what is now my C: drive, and then cloned the first drive onto the second.

    And, no I don't have a "ServicePackFiles" folder on my C-drive.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Check your WinXP SP2 CD for a i386 folder. We should be able to restore you missing files from this folder. They could be compressed. That is, instead of seeing the .exe extensions on the filenames, you will see .ex_

    If that is the case, we will have to expand them. The command prompt is used to do that. Let's see what you find first. Also, since you have a C and a D drive that are harddisks, is your CD drive letter E?
     
  17. trollface

    trollface Private E-2

    Okay, in the i386 folder, I have a REGEDIT.CH_, a REGEDIT.HL_ and a REGEDIT.EXE, but no REGEDIT.EX_. There's no files called "taskkill" or "tasklist" with any extension on the CD at all.

    And, yes, my DVD drive is E:
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since regedit.exe is not compressed, just copy it from your CD to the C:\WINDOWS\System32 folder. That should hopefully resolve your problems with regedit not working.

    Do you have WinXP Pro or Home? If it is the Home version, that is more than likely why there is no tasklist.exe or taskkill.exe.
     
  19. trollface

    trollface Private E-2

    Okay, I've done that and, yes, I'm running XP Home.

    But I've still got the same problems - System Restore doesn't work, and the computer's running very slowly.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But one of your problems was also the regedit would not work. Does it work now?

    Open a command prompt and enter the below command:

    sfc /scannow

    Did it find anything to fix? You may be ask for your WinXP CD.
     
  21. trollface

    trollface Private E-2

    Yes, REGEDIT does work now.

    I've done the scan and it did ask for the XP disc several times.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So did you supply the XP disc and let it fix the files. Did it tell you which ones?
     
  23. trollface

    trollface Private E-2

    No, it didn't say what it was fixing, but yes I did put the disc in the drive and click on "retry" whenever it asked.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! So you did not get any error messages I assume while doing this and it was able to locate all files it needed. Is that correct?

    Is the Windows XP disk you inserted a Windows XP SP2 disk? If not, you may need to check Windows Updates for updates to your OS now.

    How are things working now?
     
  25. trollface

    trollface Private E-2

    Well, it did repeatedly ask for the disc, but seemed to accept me clicking "Retry" every time. No actual error messages, no. And, yes, the disc is Service Pack 2.

    As for how things are running, exactly the same as before -very slowly when I try to actually use any processing power. And I still can't turn System Restore off, although REGEDIT and CTRL-ALT-DEL now work, and AVG no longer tells me that I've got the Backdoor.SD.Bot.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When is it very slow? What programs are you running when you believe it is slow?

    Are you the Administrator of this PC and are you currently logged in with an account that has administator priviledges? Do you get any error message when you try to disable system restore?


    Please download WinPFind

    Extract it to the root folder of drive C ( C:\ ). This will create a folder called WinPFind in the C:\ folder. Inside C:\WinPFind is a file called WinPFind.exe. Double-click on this file to launch the program. Once it is launched, click on the Start Scan button and wait for it to finish. This program will scan large amounts of files on your computer for known patterns so please be patient while it works as it can take a while, upwards to 30 minutes or more.

    When it is done, it will show the results of the scan. Click on the Copy to Clipboard button and then paste the contents of the log in your clipboard. Then save it to a file using notepad and upload the text file here as an attachment.
     
  27. trollface

    trollface Private E-2

    Well, two specifics are Fruity Loops and Halo. Fruity Loops only responds to any button-press or knob-tweak about a second later. It's made it practically impossible for me to use it as a tool, which has not been good with deadlines coming and going. It's taking me about 3 times as long to write stuff.

    Halo I just use as a kind of benchmark as it shouldn't slow down at any point with a 1024 * 768 display and all decals, particle effects and sound effects, yet even very basic set-ups without decals or particle effects are slowing right down.

    Yes, I'm the only person that uses this PC, and this logon has Admin priviledges.

    Nope. I tick the box marked "turn off System Restore" and get a popup asking me if I'm sure. I click "Yes" and the popup and System Properties box go. Then, I re-open the System Properties box and it's exactly as it was before I went to turn System Restore off.

    I downloaded WinPFind and posted a log a few posts back, but I'll run it again, if you think it'll be of value.
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These may not be malware related. They could just be due to software/hardware conflicts on your PC or some other aspect of the software possibly requiring a reinstall.

    Please boot into safe mode and locate and rename the files given below:

    C:\WINDOWS\SYSTEM32\dprsx.dll rename to dprsx.ddd
    C:\WINDOWS\SYSTEM32\msasf.exe rename to msasf.xxx
    C:\WINDOWS\SYSTEM32\rdtapjv0.ini rename to rdtapjv0.iii
    C:\WINDOWS\SYSTEM32\t3lujmpq.ini
    rename to t3lujmpq.iii
    C:\WINDOWS\SYSTEM32\u6oiurji.ini
    rename to u6oiurji.iii
    C:\WINDOWS\system32\A80103E9AD.sys
    rename to A80103E9AD.sss

    Then reboot into normal mode and tell me if you get any error messages. Also let me know if there is any change to any of your problems.

    Also download GetService.zip from here: Getservice.zip

    Extract the file to a folder where you can find it, then go to the folder and double-click on the getservices.bat file. A notepad will open up. Please paste the contents of that notepad file as an attachment too. Call it service.txt.
     
  29. trollface

    trollface Private E-2

    But they worked fine a few weeks ago, and I've not installed or upgraded anything since. Well, until this thread, at least.

    Okay, I've renamed all the files listed, and I got no error messages.

    The GetService file is attached.
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download the attach GetRunKey-V114.zip to your PC someplace you can locate it. Then extract the getrunkeys.bat file from the ZIP. Locate the getrunkeys.bat file and double click on it to run it. It will create a file named runkeys.txt in the root of drive C: (C:\runkeys.txt) . This log will also popup in a notepad window which your can just close. Unload the runkeys.txt file here are an attachment.
     

    Attached Files:

    Last edited: Dec 6, 2005
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! It is possible that something is still hiding. We may need to dig deeper. However it does not make sense that only two programs would be affected by whatever malware could potentially be hiding. It would make more sense that everything would be slower.
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  33. trollface

    trollface Private E-2

    Okay.

    That System Restor troubleshooting didn't help, and there's no error messages relating to it that I can find. The runkeys text is attached.
     

    Attached Files:

  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download F-Secure Blacklight to its own folder (someplace you can find it).

    After download is complete, double click on the blbeta.exe file run the program. Click "Accept" to continue and then click SCAN to begin scanning your system.

    Once the scan is complete it will attempt to clean the found infections. There should be a log in the folder that you ran the program from, attach this log to your next post.
     
  35. trollface

    trollface Private E-2

    Well, I think it's actually something saved in the System Restore folders that may be the problem. About 15 minutes ago AVG came up with an infected file, and I copied down the name before Healing it (I don't expect Healing it to actually work, you understand, but I didn't want to delete it, and I wasn't about to leave it). Anyway, the address is c:\System Volume Information\_restore{E8FA4EA7-F2A0-4490-A6C6-DA0667083E82}\\RP162\A0087774.exe Does that help with anything?

    I've finished that scan, but it didn't find anything. I've attached the log anyway.
     

    Attached Files:

  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well this is why we try to disable system restore but since you cannot, who knows what is in there.

    The information you gave just indicates a typically system restore type file name. What virus or malware was found?

    If you still have problems, I would just boot into safe mode, try again but while in safe mode to diable system restore and then try delete that whole RP162 folder. If System Restore does not get disabled this will be denied.

    If that does not work! Boot into normal mode and download the below registry patch to your Desktop.

    http://www.kellys-korner-xp.com/regs_edits/disablesystemrestore.reg

    Once downloaded double click on it and answer yes to add it into your registry. Check to see if system restore is disabled now.
     
    Last edited: Dec 9, 2005

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds