explorer.exe and IRC.Backdoor.Trojan....Help Please!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by mjm, Apr 19, 2006.

  1. mjm

    mjm Private E-2

    I am at wits end and really hope you guys can help out.

    I continue, after all efforts to fix it, to get a warning window from Norton that tells me I have IRC.Backdoor.Trojan.

    Have a false explorer.exe running in the processes window. Killbox will not kill it.

    Well I figure that is what Norton is there to fix. Hmmm….

    Did all the steps shown in the Sticky page here at Majorgeeks and am attaching to this post the request logs from Activescan, Bitdefender, and Hijackthis.

    One weird thing I am noting everytime I start up is a “Windows Installing…” message followed by a window that says: “Norton antivirus 2005 does not support the repair feature. please uninstall and reinstall.” Not Entirely sure how this gets to be, but as a person who condiers themselves fairly computer savvy, I am stuck in a major way.

    Please Help……
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\DOCUME~1\Owner\LOCALS~1\Temp\mdm.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://192.168.1.1/
    R3 - Default URLSearchHook is missing
    O4 - HKLM\..\Run: [Debug ] C:\WINDOWS\SMSS.exe
    O4 - HKLM\..\Run: [Bsx3] RunDLL32.EXE C:\WINDOWS\bs3.dll,DllRun

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :

    C:\Documents and Settings\Owner\Local Settings\Temp <--- delete all files in this Temp folder
    C:\Documents and Settings\Sachi.HOME\Local Settings\Temp <--- delete all files in this Temp folder
    C:\Documents and Settings\Owner\Desktop\software DVD stuff\PodPlus.v1.2.Incl.Keygen-TMG.rar
    C:\Documents and Settings\Owner\Desktop\software DVD stuff\setupneoaudio.exe
    C:\PROGRAM FILES\Lycos <--- delete this folder
    C:\PROGRAM FILES\save <--- delete this folder
    C:\PROGRAM FILES\COMMON FILES\Slmss <--- delete this folder
    C:\WINDOWS\cdapp <--- delete this folder
    C:\WINDOWS\SMSS.exe
    C:\WINDOWS\bs3.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  3. mjm

    mjm Private E-2

    Many thanks on the reply. I am very eager to give it all a shot.

    Am at work now and will follow advice when I get back to home computer. I live in Tokyo so this will be about 12 hours from now (Coming up on 4pm PST).

    Best,

    Mike
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Just let me know how things look when you finish.
     
  5. mjm

    mjm Private E-2

    Okay, followed your directions to the letter. Seems much better straight off. That said, I am still getting the following:

    At start-up the same Windows Installer window came up and then gave me the same messaga about Norton *i.e. “Norton antivirus 2005 does not support the repair feature. please uninstall and reinstall.” )

    I then proceeded to open a Netscape window. Looked at the processes running (CTRL+ALT+DLT)after that opened. No funky explorer.exe.

    Then I opened an Internet Explorer window. Same proscesses check. No funky explorer.exe., just a www.majorgeeks.com session. :)

    Then the ugly happened. My Norton window alerting me of IRC.Backdoor.Trojan pops up saying repair failed. I had to click OK twice and then it stopped popping up. I exited Explorer and tried to repeat the event. I could repeat it successfully.

    I went into D&S/OWNER/LOCAL/TEMP and deleted the hpb.dll that was shopwing as the Norton threat.

    After closing Explorer, and staying connected to the Internet, no further Norton Ugly Red Windows.

    Am I correct in assuming that whatever generates this .dll is still there albeit severely hindered or injured due the cleaning steps i took as per your note? It seems we are almost there. I will get to sleep now and check for your post in the morning here (about 10 hours from now).

    I am attaching the new HJT log to this note.

    Many thanks so far and I shall be keen to get this whipped.

    Speak to you in a few...

    Mike
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First work through the below link from Norton (this is not a malware issue).

    http://service1.symantec.com/SUPPORT/nav.nsf/docid/2004090712504306?OpenDocument&wsrc=hho&src=hot&prod=Norton+AntiVirus&ver=2005&csm=no&seg=hho

    See if it helps resolve your problems with Norton. If not, I suggest uninstalling it and using one of the free programs we list in the below link:

    How to Protect yourself from malware!

    The above link also gives some free firewalls you can use in step 3.

    You also need to be more careful with what you are calling processes. You keep saying Explorer or explorer.exe but it sounds like you really mean Internet Explorer which is iexplore.exe. Explorer (which is explorer.exe) is Windows Explorer which is also the Windows Shell.
     
    Last edited: Apr 21, 2006
  7. mjm

    mjm Private E-2

    Hi,

    Have printed the Norton page and will get that done this evening when I get home. That should resolve the window popping up at start up.

    As for the processes thing, I am using that term as it is what the window that appears when I hit "(CTRL+ALT+DLT)" calls them. I may well be clean now, but the earlier porblem was that something called (in lowercase letters) "explorer.exe" followed by a hyphen and MSN.com was showing up. I could not kill it for love nor money. After following your recommended steps yeterday, this little gem is not popping up. Looks like your advice solved that issue. Many thanks.

    I am still curious what to do about this IRC.Backdoor.Trojan that Norton thinks it is finding. Is this related to this hpb.dll and therefore worth being concerned about? (i.e. i something still in there somewhere generating that .dll?) Or is something that after putting the "Portal" and "Incoming" folders in the Norton Quarantine folder I will be protected from in the background?

    Really appreciate all the time and effort you are putting into this. My blood pressure rise from the virus has dropped several points merely by having yoru help. Thanks and speak to you soon.

    Best,

    Mike
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't know for sure. It does not sound like a valid file. Where is it being located? Have you deleted the file yourself manually? Have you emptied your Norton Quarantine? Does the file still exist?

    Who knows how well your Norton AV is working since you have other problems with it.
     
  9. mjm

    mjm Private E-2

    Hey Chas,

    Nearly there, but...............

    Back at the keyboard after the weekend. More info for you to digest is as follows:

    I started in normal mode after getting the NAV folders back where they neede to be. All seemed well in the world. Opened and closed Netscape a few times without issue. No Norton messages about the Trojan.

    The hitch came when I opened Internet Explorer. Figured I had to biote the bullet and see if that worked welkl now also. Unfortunately not. Here is what I noted:

    1) At the same time of creation as the time at which I opened IE, 1 example of the hbd.dll appeared in Owner/Local Settings/Temp

    2) 5 examples of hbd.dll appeared in the C:\Recycler folder

    3) This .dll is 40kb.

    Into Safe Mode I went.

    I deleted the stuff in the Quarantine folder
    I deleted the files in the Recycler folder.
    I delete the one from the Temp Folder.

    Restarted in Normal and if I do not use IE, the woprld seems normal. Problem is I need IE for certain things. Hmmmm..... Just being patient until I can get this resolved.

    On Startup I also note the following being created in the Temp Folder:
    1) ZGTemp Folder (files.mcs, and files.mct)
    2) ~DF2857.tmp

    Have attached new HJT log to this note and await yoru wisdom eagerly.

    Thank you in advance,

    Mike


     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You show signs of a Smitfraud infection coming and going! See the below:

    O2 - BHO: Nothing - {edbf1bc8-39ab-48eb-a0a9-c75078eb7c8e} - C:\WINDOWS\system32\hp449A.tmp (file missing)

    You MUST NOT fix things on your own. If you do, I cannot see what is going on and I cannot determine what the correct steps are. So do not fix anything unless I request it. Also at this point I'm close to saying uninstall Norton (at least while we work on fixing things). Run IE just to try and get the problem back. Then run the steps in the below (many of the items being mentioned will not be seen, that's okay! Just complete all the steps and check for all things mentioned anyway. ) Then attach the smitfiles.txt log when finished.

    SpywareStrike, Smitfraud, SpySheriff, SpyAxe & PSGuard Removal

    Then attach a new HJT log and tell me what your status is.

    Also tell me what is the below used for:

    C:\Program Files\NTTE\Flets\app\TangoService.exe
    Is it for your Efficient Networks DSL modem! Are you in Japan (I see NTTE.)
     
  11. mjm

    mjm Private E-2

    Hi,

    I did indeed get the Smitfraud infection from a link a friend sent me over the weekend. I went to the link you reference below and got rid of it. Worked like a charm in fact. When I get back tonight I can send the smitfiles.txt file if needed. Lovin' your BB and wish I could send a case of decent Ale somewhere as a thanks.

    So in effect the HJT log attached to my note earleier today is the latest one post running the steps in the link you reference for Smitfraud.

    The Flets link is actually a necessary piece of software to allow me to coonect via my fiber-optic connection to NTT. I am indeed in Tokyo. That has been running problem free for many moons.

    So given that the HJT log was created after the smitfraud removal, I guess the next thing is to try and recreate the effects opening IE and see what is what. Gioven that the smitfraud steps are domne, need i run them again? Happy to do so, just checking.

    I also note that Firefox Mozilla is a recommended replacement for IE as per your sticky. Should I simply go ahead and do that now if IE files are a problem?

    Thanks again,

    Mike

     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well you can use FireFox but we still need to get IE fixed for cases when it is required like even getting MS updates. So give me the Smitfiles.txt log and then also get a new HJT log from after running IE. If problems are coming back, I need to see them so do not fix anything. Let me see them.
     
  13. mjm

    mjm Private E-2

    Roger that. It is 2pm here so I will get this off to you in about 8-9 hours.

    Speak to you soon,

    Mike

     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yeah well it's 2:49 AM here and I'm finally going to bed! :D
     
  15. mjm

    mjm Private E-2

    Okay here is some stuff for you to chew on. I am about ready for bed here now but will send this off as you will be up before me. :)

    Opened IE and get "about:blank" in the bar. I had that set to a place called majorgeeks.com a day ago. Pray tell what evil thing has come into my life now? No hpb.dll files popping up that I can se and Norton is not flashing ugly red windows at me, and best of all the tasks running do NOT include the phantom explorer.exe I was getting before. Is it too early to whoop and yell with joy about that little mystery?

    In any case, I am attching the smitfiles.text log and the new HJT log to this note.

    Will speak to you in the morning........

    Mike
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have it set to about:blank. It is not set to majorgeeks. You must set your home page to what you want and you must allow the change to be accepted by Windows Defender and similar programs or they will block the change. In fact you will need to exit MS Windows Defender to do the below so exit it by right clicking on the icon in the tray and shut it down or exit it. Do this now.

    It's not a mystery. You had a Smitfraud infection.

    Then run HJT and fix the below line and make sure it stays gone after a reboot:

    O2 - BHO: Nothing - {edbf1bc8-39ab-48eb-a0a9-c75078eb7c8e} - C:\WINDOWS\system32\hp449A.tmp (file missing)

    Make sure after reboot that you allow any changes to occur if you see a warning message from Windows Defender, otherwise it will block your home page change and possibly the above fix.
     
  17. mjm

    mjm Private E-2

    As usual, a million thanks for the note. Will do this stuff this evening.

    Speak to you shortly,

    Mike
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Let me know when you are finished.
     
  19. mjm

    mjm Private E-2

    Morning,

    All done with those last few steps. Seems the world is in order again.

    Posting HJT log with this note. One item though, I have no windows defender icon in the tray and although I can ope it easily from Programs menu, I could not see how to egt it to be an always on item.

    In any case, let me know what you think. Am I now ready to go do the various steps in the "Protect from Malware" sticky? I feel like a ton of bricks has beeen lifted form my shoulders so far.

    Many thanks indeed.

    Speak to you soon,

    Mike
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As far as I know, that is how Windows Defender works. It does not show an icon in the tray like MS Antispyware did. I believe the option that loads it at run time causes it to be hidden by default. There is no menu select to choose in order to show a tray icon like MS AS had.

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  21. mjm

    mjm Private E-2

    Right On! You guys rock and deserve mass quantities of Celebration Ale.

    Will gladly get to the last couple of steps this evening.

    10 out of 10 for Major Geeks!

    Thanks,

    Mike

     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds