Backdoor.Win32.Aimbot.aj

Discussion in 'Malware Help (A Specialist Will Reply)' started by joejoe172833, Dec 16, 2006.

  1. joejoe172833

    joejoe172833 Private E-2

    I have ran all of the stuff in the read me run me thread and there was nothing special to post. My Security suite seems to be getting rid of most of my problems except for Backdoor.Win32.Aimbot.aj. I have tried alot of thing and cannot figure it out. I have posted a hijackthis log for you to look at as well.
    thanks.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We need all the requested logs from the READ ME!

    CounterSpy
    Bitdefender - from step 6
    Panda Scan - from step 6
    runkeys.txt - the log from GetRunKey.bat
    newfiles.txt - the log from ShowNew.bat
    HijackThis



    Also you did not follow the directions in step 7 to rename HijackThis. As stated, this is very important.
     
  3. joejoe172833

    joejoe172833 Private E-2

    I could not get bit defender to work but here are the first three
     

    Attached Files:

  4. joejoe172833

    joejoe172833 Private E-2

    here are the other two and I renamed hijackthis.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmmm! Your first message said
    That is quite a bit incorrect wouldn't you say? There were about 35 items in your Panda log alone. And in CounterSpy there were 7 items which you chose to Ignore! Why didn't you fix the items that CounterSpy ran? That is the whole purpose of running the scans. Run CounterSpy again now, and have it fix everything and then attach a new log.
     
    Last edited: Dec 17, 2006
  6. joejoe172833

    joejoe172833 Private E-2

    Yeah sorry, Things have gotten quite a bit nastier in the last couple of days. I thought I had this problem under controll after I ran the stuff but it all went down hill from there.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! While I look thru all your other logs and work up fixes, please re-run CounterSpy now and have it fix all that it finds. Then attach a new log from CounterSpy.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below old versions of software:
    J2SE Development Kit 5.0 Update 8
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 8
    J2SE Runtime Environment 5.0 Update 9
    Mozilla Firefox (1.5.0.8)
    Peer Points Manager

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox

    If you need the Sun Java Development kit you can get it here: http://java.sun.com/javase/downloads/index.jsp

    What is this?
    O4 - Global Startup: postcon.bat

    Does it have something to do with Lclock?

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\WINDOWS\mcache32.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Device cache manager] C:\WINDOWS\mcache32.exe -a
    O4 - Global Startup: postcon.bat
    O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZJfox000
    O18 - Filter: text/html - (no CLSID) - (no file)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    C:\Documents and Settings\Home\Local Settings\Temp\ADMCache\adm38F.tmp
    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\DEEZ6ABE\update182fs[1].exe
    C:\Program Files\Mozilla Firefox\chrome\m3ffxtbr.jar
    C:\Program Files\Mozilla Firefox\chrome\m3ffxtbr.manifest
    C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll
    C:\Program Files\Mozilla Firefox\plugins\NPNd2fn.dll
    C:\WINDOWS\Downloaded Program Files\MediaTicketsInstaller.ocx
    C:\WINDOWS\system32\actskn45.ocx
    C:\WINDOWS\system32\closeapp.exe
    c:\windows\system32\dsmanager.dll
    c:\windows\system32\f3PSSavr.scr
    c:\windows\system32\Inkline Global PC tuneup.ico
    c:\windows\system32\unPPC.exe
    C:\WINDOWS\system32\winmap.exe
    C:\WINDOWS\system32\msnpg.exe
    C:\WINDOWS\system32\msconfig32.exe
    C:\WINDOWS\system32\mscgdc.dll
    C:\WINDOWS\system32\msodae.dll
    C:\WINDOWS\system32\P2P Networking v126.cpl
    C:\WINDOWS\mcache32.exe
    c:\windows\smdat32m.sys
    C:\WINDOWS\ggldzokwltx.exe
    C:\WINDOWS\stubinstaller6282.exe
    c:\windows\thin-143-1-x-x.exe
    c:\windows\ubber60.ini
    c:\windows\usta33.ini
    c:\windows\webdlg32.inf
    C:\WINDOWS\winsx.inf
    c:\temp\salm_kyf.dat

    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folders and delete if found:
    C:\Documents and Settings\Home\Application Data\FunWebProducts
    c:\documents and settings\all users\application data\vidctrl
    c:\program files\common files\Download
    C:\Program Files\Need2Find

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Home\Local Settings\Temp

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  9. joejoe172833

    joejoe172833 Private E-2

    heres is the new counter spy log and I sent a new hijackthis log as well
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still told CounterSpy to Ignore:
    Need2FindBar
    Fun Web Products
    MyWebSearch Toolbar
    Altnet Download Manager

    I believe that I said you need to
    .

    Please run it and fix EVERYTHING! My previous steps will be incomplete unless you fix all these. They are malware and they MUST be fixed. I would not even waste time quarantining them. I would delete them.
     
  11. joejoe172833

    joejoe172833 Private E-2

    I fixed the stuff with counter spy and followed the steps you gave me when I ran kill box I got the message "PendingFileRenameOperations".

    After rebooting I could not find
    C:\documents and settings\all users\application data\vidctrl
    C:\program files\common files\download
    C:\program files\need2Find

    Sorry to make this so hard on you.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean! If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  13. joejoe172833

    joejoe172833 Private E-2

    I am still coming up with Backdoor.Win32.Aimbot.aj on my spyware scan with freedom antispyware
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Attach a log that shows exactly what this tool is finding?

    It could be just finding some left over registry keys like the below:

     
  15. joejoe172833

    joejoe172833 Private E-2

    I cant make a log from the antispyware list but the only thing listed is
    Backdoor.Win32.Aimbot.aj

    It says the location is: key"hkey_local_machine\system\currentcontrolset\e....

    Threatens: Unknown
    Certainity: Confirmed
    Risk: Unknown
    Category: Backdoor
    Advice: Unknown
    Author: Unknown Author
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well that is not a complete log. You need a better tool if that is all the info it gives and if it will not fix it. Try the below:


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  17. joejoe172833

    joejoe172833 Private E-2

    I tried that and when I did it showed the same thing im trying find a way to make a better log of the stuff for you to look at.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may have lost ownership priviledges of the registry key.

    Please download and install Registrar Lite Make sure you select a Majorgeeks download link and not the Authors!

    Run Registrar Lite navigate to each of the following key and take ownership of it (I explained how to do that further down).

    HKEY_LOCAL_MACHINE\system\currentcontrolset

    To take ownership of the key do the following:
    • Copy & Paste the registry key from above into the Address bar of Registrar Lite and hit the enter key. This will bring you to the registry key.
    • Click-on Security in the top Menu
    • Select Take Ownership
    • Repeat these steps for all of the registry keys given above before continue to the next steps below.
    • Now leave RegistrarLite running and continue
    • Now run the fixME.reg REGISTRY PATCH I previously gave you again.
    • Tell me the results. Any error messages?
    • Now in RegistrarLite click View and then Refresh
    • Now navigate one at a time to each below registry keys and make sure they are gone:
      • HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_msdirectx
      • HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_msdirectx\0000
      • HKEY_LOCAL_MACHINE\system\currentcontrolset\services\msdirectx
    • If any of these keys still exist, right click on it and select Delete. Make sure you are select those exact registry keys only.
    • Let me know if you have to do this and if you get any error messages at this point.
     
  19. joejoe172833

    joejoe172833 Private E-2

    I did not get any error messages when I ran the fixME.reg patch. I did have to delete:

    HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_msdirectx
    HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_msdirectx\0000

    but did not get any error messages when I did it.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So does this mean that your freedom antispyware comes up clean now?
     
  21. joejoe172833

    joejoe172833 Private E-2

    freedom came back with two entries for registry cleaner. and I could not get back on the internet and had to restore
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what you mean by registry cleaner. Is that exactly what it said? There are many programs that do registry cleaning. Why couldn't you get back on the internet? Did you have Freedom fix whatever it was reporting and then you could not get back on the internet? I thought this Freedom security suite just package Authentium's Command AV and Pest Patrol's Antispyware program together (and perhaps there is a firewall & parental controls too).


    Are you saying you used System Restore? What point in time did you revert too? Did you clean the restore points in message # 12 or did you never do those steps? Did the restore bring back the issue with Backdoor.Win32.Aimbot.aj
     
    Last edited: Dec 18, 2006
  23. joejoe172833

    joejoe172833 Private E-2

    It said registry cleaner and was listed as an application. When I started firefox it said there was a problem and it needed to close. When I started IE it said that it could not load the page no matter what address I used. I called Time Warner to make sure the problem wasnt on their side and they told me it was a problem with my computer, they couldnt help.
    Freedom had fixed the problems before I tried to get online.
    When I rebooted my computer this morning I got the message that windows encountered a problem and asked how I wanted to start I tried it a couple of times in both starting normally and in safe mode but it just went back to the same screen.
    I restored to the point right before I ran the registrar lite program, and yes the Backdoor.win32.aimbot.aj is there again
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you mean Registrar Lite? It is not really a registry cleaning tool!

    Sounds to me like Freedom did something it should not have.

    Well then you will have to clean up again. But you did not answer whether you had ever completed those final steps instructions??
     
  25. joejoe172833

    joejoe172833 Private E-2

    Yeah I completed all of the steps. I will go back and clean it up again and I will tell freedom to ignore it this time.
     
  26. joejoe172833

    joejoe172833 Private E-2

    OK that done it I didnt pick it up this time. and I turned system restore off and rebooted and then turned it back on. I think that covered it. Thanks alot once again.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Don't forget that now your only restore point is the one just created after toggling System Restore. Obviously there will be new one created at various points when you reboot, but your oldest one is now the one just made. As long as you are clean when this was made, it is all you need!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds