Bkdr Haxdoor.bc

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Lemboskities24, Mar 30, 2005.

  1. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Boot into Safe Mode and try it again!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. Lemboskities24

    Lemboskities24 Private E-2

    Ok I got rid of the zone labs thing and download SP1 and all of the other recommended updates. However, SP2 will not show up.
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    If you have SP1 installed, go back to windows updates and you will see it, I promise!
     
  5. Lemboskities24

    Lemboskities24 Private E-2

    I did, I don't see it...I took a screen shot of it.
     

    Attached Files:

    • SP2.JPG
      SP2.JPG
      File size:
      78.4 KB
      Views:
      25
  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Choose this and see if its here:

    Select optional software updates

    Also, Please attach a current HJT log.
     
  7. Lemboskities24

    Lemboskities24 Private E-2

    I clicked it the "Select optional software updates" button and it froze up. I tried 3 times.
     

    Attached Files:

  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    wuauclt.exe <-- This process is Windows Update AutoUpdate Client. Do you see Service Pack 2 in here as an option to download & install?

    Your log still looks ok, thats a good thing. Now we got to get SP2 installed.
     
  9. Lemboskities24

    Lemboskities24 Private E-2

    what? I don't get it.
     
  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Automatic Updates, this is currently running, open it. Now, do you see Service Pack 2 to download and install?
     
  11. Lemboskities24

    Lemboskities24 Private E-2

    Can't find my Auto Updates Icon, it's not on my task bar like it usually is when it has an update for me.
     
  12. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I have requested a second set of eyes on this one, hang in there a few moments.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please click the below link:

    http://v5.windowsupdate.microsoft.com/v5consumer/default.aspx?ln=en

    Do you see two choices in the middle of the screen with the below text:


    http://v5.windowsupdate.microsoft.com/v5consumer/shared/images/arrow.gif Express Install (Recommended): High Priority Updates for Your Computer
    Choose this for the fastest updating. Quickly scan for, download, and install only the critical and security updates your computer needs.
    http://v5.windowsupdate.microsoft.com/v5consumer/shared/images/arrow.gif Custom Install: High Priority and Optional Updates for Your Computer
    Choose this to scan for optional, critical, and security updates your computer needs, choose from all the updates on the site, and review updates before downloading.

    If so, choose Express Install. It should show any High Priority updates which should include SP2. If it does not, back up and choose Custom Install. What is in that list?
     
  14. Lemboskities24

    Lemboskities24 Private E-2

    heres a screen of what comes up for "Custom Install"
     

    Attached Files:

    • SP2.JPG
      SP2.JPG
      File size:
      83.5 KB
      Views:
      26
  15. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Click on Select optional software updates and attach another screenshot.
     
  16. Lemboskities24

    Lemboskities24 Private E-2

    This one is after I hit "Select optional software updates"

    It gives a Picture in picture kind of effect.
     

    Attached Files:

    • SP2.JPG
      SP2.JPG
      File size:
      75.2 KB
      Views:
      27
  17. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Something really weird is going on, Chaslang will be back in a moment.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure what you posted in message #64 was not for Express Install?
     
  19. Lemboskities24

    Lemboskities24 Private E-2

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    OK! From the window you show in message #66 pick the View Installation History option and show us the first screen that comes up for that.
     
  21. Lemboskities24

    Lemboskities24 Private E-2

    page 1 out of 4

    I can't access the other ones for some reason, I get the Picture in Picture thing again.

    Edit: nevermind I take that back
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does the right side of the screen show the Source as Automatic Updates?

    And does your Windows version still show as Win XP SP1?
     
  23. Lemboskities24

    Lemboskities24 Private E-2

    Pages 2 and 3
     

    Attached Files:

  24. Lemboskities24

    Lemboskities24 Private E-2

    page 4
    all of the fails were from that zonelabs nightmare

    sources vary between Atuomatic Updates and Windows Update wedsite

    Where do I see my windows version?
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Right click MyComputer and select Properties or look at the top of a current HJT log.
     
  26. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Post #57

    HJT log:

    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)


    This was after I requested SP2 but couldnt find it on WU. Thats the problem now, getting SP2 installed.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I just want to double check that is what it still says!
     
  28. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    okay!:)
     
  29. Lemboskities24

    Lemboskities24 Private E-2

    yup still the same
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  31. Lemboskities24

    Lemboskities24 Private E-2

    thank god for cable internet...this will only take...7 minutes(atleast thats what the download thing says)
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Cool! After you downloaded it and install it! Let us know how everything looks!
     
  33. Lemboskities24

    Lemboskities24 Private E-2

    will do, I can't tell you guys how much I appreciate all of this. I am really lucky to have stumbled across this site.
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! We're happy to help!

    But now it is time for me to get some sleep!
    Good Night!
     
  35. Lemboskities24

    Lemboskities24 Private E-2

    Ok downloaded the update and here is the HTJ log you wanted.

    I can't seem to get desktop icons to stay where they are, I restart and they disappear.
     

    Attached Files:

  36. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your HJT log is now clean!

    Are you having any further problems? About the desktop icons explain exactly whats going on so I can rule out some things.
     
  37. Lemboskities24

    Lemboskities24 Private E-2

    Ok first of all this virus wiped my desktop clean of icons so I need to put new ones on. When I create the shortcuts and add them to the desktop they are fine. After I restart the icons multiple into duplicates(I'll attach a screen) and if I delete one of the duplicates and restart they all get deleted.
     

    Attached Files:

  38. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Click Start > Run > type in regedit

    Navigate to the following keys:

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop
    Do you have this key? If so, are there any values?

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
    Do you have any other values than NoDriveTypeAutoRun in this key?
     
  39. Lemboskities24

    Lemboskities24 Private E-2

    took screens, here they are.
     

    Attached Files:

  40. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Click Start > Run > type in regedit

    Navigate to the following keys:

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop

    Right click and delete every DWORD Value, leave the (Default) string.

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer

    Right click and delete every DWORD Value except NoDriveTypeAutoRun, leave the (Default) String.

    This should take care of your problem, if not let me know!
     
  41. Lemboskities24

    Lemboskities24 Private E-2

    looks good, thanks for all of the help and hopefully I won't have to come back anytime soon. :p
     
  42. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    So everything is ok now, no further problems?
     
  43. Lemboskities24

    Lemboskities24 Private E-2

    Everything is ok. Again I really appreciate all of the hardwork and effort.
     
  44. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your Welcome!:)

    You should check out this article on How to Protect yourself from malware!
     
  45. Lemboskities24

    Lemboskities24 Private E-2

    Oh dear lord no....the I was wrong about the desktop icon bit being fixed :( :confused: they still come up in doubles.
     
  46. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Whats the exact problem?
     
  47. Lemboskities24

    Lemboskities24 Private E-2

    same as before, I try and put on a desktop icon and when I restart it their are 2.

    I told you this couldn't last...I can't start my games up or install them.
     
  48. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    What do you mean by this, what happens?
     
  49. Lemboskities24

    Lemboskities24 Private E-2

    I put the cd in the drive and the game begins to start up, it freezes right before the actual game comes up and it's there until it says "(not responding)" same thing for installing.
     
  50. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Okay! Last Resort :eek:

    Download Kaspersky Anti-Virus Personal 5.0 as it cleans this thoroughly + much of the crap that comes with it!! This version is a 30 day trial.

    You should print this out for reference!

    You must disable any AntiVirus programs you have installed

    Now install KAV 5.0

    When Installing, do the following as you come to them (if they appear):

    Uncheck the Operate According to Recommended Settings Box

    Uncheck the Use Real-time Protection against Network Attacks Box

    Uncheck the Use The iStreams Technology Box

    Now, allow KAV 5.0 to download and install Updates. Then, look under Settings > Configure Updater and select Extended Database > OK > Check for Updates and allow those to install.

    Then, Click Settings > Configure On-Demand Scan Settings and Set Scan Level to Maximum > Perform Recommended Action > OK

    NOW, Close ALL Programs (including KAV 5.0) and Browsers!

    Physically Disconnect from the Internet - Pull the Cable!!

    Boot into SAFE MODE

    OPEN KAV 5.0 BUT DO NOT RUN IT YET!!!

    Open Task Manager (Ctrl-Alt-Del) and RightClick explorer.exe and END IT! Don't be alarmed when all of your desktop items disappear. That is normal.

    Everything will go blank except for KAV 5.0 and Task Manager. DO NOT CLOSE THEM!!

    Now : Start a FULL SYSTEM SCAN. Click the Protection Tab and select Scan My Computer .


    This process may take HOURS . . . . LET IT RUN!

    When the Scan and Cleanup are done, go to Task Manager and select File / New Task and type explorer.

    Close KAV 5.0 and TaskManager and reboot to Normal Windows and and let me know the results from this scan.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds