haxdoor e

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by SDrake, Oct 11, 2009.

  1. SDrake

    SDrake Private E-2

    Hello, this is my first time posting here for help with a malware situation. I apologize if everything is not correctly formatted but I tried my best to follow the "READ AND RUN ME FIRST" instructions.

    "Clearly describe in detail the problems you are having and how long ago they started. Think about what you were doing at the time."

    Yesterday while browsing I got an alert from McAfee that a program named "n.exe" (or something to that effect, I closed the box before taking down the name) was requesting access to the internet. I clicked Block All Access and scanned with the CA Yahoo! Anti-Spy. Results said I had the backdoor malware "haxdoor e". I immediately attempted to scan with Malwarebytes' software but nothing would come up. I reinstalled and renamed the file but only recieved an error saying that the executable file could not be found.

    I then scanned with AVG and SUPERAntiSpyware with nothing but tracking cookies and one trojan coming up. After cleaning it still showed up and Malwarebytes' still couldn't run. I then started running the "READ AND RUN ME FIRST" software, CCleaner which seemed to clear the "haxdoor e" until I reconnected to the internet and scanned again with CA Yahoo! Anti-Spy which pulled up Win AntiVirus Pro 2006, WinSpyware Protect, and Bifrost this time.

    I ran the Windows XP Cleaning Procedure and got the logs with the exception of Malwarebytes'. I have uninstalled AVG so I only have one antivirus program but McAfee isn't verified (had to renew subscription). I'm afraid to verify it now and I don't think I can verify from another computer. I have seen no symptoms yet but from what I read it seems like it's more about keylogging and such and I'm worried about my personal information.

    Any help would be greatly appreciated.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hello and welcome. I am currently reviewing your logs and will get back to you with a set of intructions as soon as possible. Thanks for your patience during this time.

    Kes13!

    FYI:

    Important Notice: A new version of SUPERAntiSpyware is out.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this log later.
     
  3. SDrake

    SDrake Private E-2

    Hello Kestrel13, thank you I really appreciate your time. Here is the new log for SUPERAntiSpyware.

    Upon restarting though I got two errors

    "this application or DLL C:/WINDOWS/system32/jukazena.dll is not a valid Windows image. Please check this against your installtion diskette.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Before we continue please use MSCONFIG to put this machine back into Normal Start-up Mode.

    2. Please go to add/remove programs and uninstall the following software:

    • Java(TM) 6 Update 15

    3. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix exit HJT.

    4. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    Viewpoint Manager Service
    
    File::
    c:\windows\popcinfot.dat
    c:\windows\system32\jukazena.dll
    c:\windows\system32\rovonahu.dll
    C:\WINDOWS\system32\yogiteze
    
    Folder::
    C:\Program Files\Viewpoint\Common
    c:\documents and settings\All Users\Application Data\Viewpoint
    c:\program files\Viewpoint
    c:\documents and settings\Wesley Peterson\Application Data\Viewpoint
    c:\documents and settings\All Users\Application Data\avg8
    
    Registry::
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
    "Notification Packages"=hex(7):73,63,65,63,6c,69,00,00 
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=""
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{28123d62-2e40-4dbe-8a18-da07fa988b0e}]
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    5. Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    6. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    7. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  5. SDrake

    SDrake Private E-2

    Alright, posting from another computer got a few questions. Got it back to normal mode start up and uninstalled Java.

    When I ran HijackThis I didn't find that first line

    O2 - BHO: (no name) - {28123d62-2e40-4dbe-8a18-da07fa988b0e} - rovonahu.dll (file missing)

    but did fix the other one.

    Running ComboFix now, had to update and install the recovery console although I thought I did the first time I ran it. Turned off my other virus-scan software (I thought) but the McAfee firewall or whatever popped up and I think it's stalled at stage 23 even though I let it pass.

    Should I just close it and drag the script on it again?
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    First search your C drive for a combofix.txt file (check the date on it so you can see it's the correct log) if it is not present and a log wasn't generated, then yes, you will need to re-run the script, and then once done, run mgtools again and attach the zipped logs from running that.

    Thanks
    Kes13
     
  7. SDrake

    SDrake Private E-2

    Alright, here they are.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Your logs are clean :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  9. SDrake

    SDrake Private E-2

    Good to hear, thanks for all your help Kestrel13!

    Seems to run fine now, Malwarebytes' runs again. Only two things that kinda bug me.

    I have that Windows Security Alerts red shield pop up in the bottom right telling me McAfee VirusScan might be out of date. Is it one of those fake alerts don't recall seeing it before, could I still be infected a bit or could it be from running on normal startup again? Both Malwarebytes' and SUPERAntiSpyware come back clean.

    Second thing would be what is the consensus on CA Yahoo! Anti-spy? I ran that and it still came up with WinSpyware Protect and WinAntiVirus Pro 2006. Could it just be a bogus result or some kind of conflict from running all the other software? Should I uninstall it?

    Other than that though runs fine, thanks again for the help. Any info about those questions would be appreciated but if not I understand, as you guys are pretty busy.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Has your subscription for your anti virus ran out? Was it paid for or just a free trial?

    Where exactly is it finding these threats? It could just be something trapped inside system restore.

    Complete the final steps, answer my above questions and let me know how things are going.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  11. SDrake

    SDrake Private E-2

    McAfee is a paid version subscription ran out a couple weeks before, hadn't renewed it yet. Hadn't see it until just recently after I got infected. Seems legit since McAfee VirusScan really is turned off (just the firewall stays on) until you renew, but just curious.

    As for the stuff Yahoo found it already cleared it, haven't seen it since but I believe it was in My Computer/HKEY_CLASS_ROOT/*/shellex

    Completed the final steps. Everything runs fine except the internet is a bit slow sometimes but I think that's just my connection.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good to hear :) Safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds