Haxdoor-H and CoolWWWSearch infection

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by AVIS, Mar 7, 2005.

  1. AVIS

    AVIS Private E-2

    1. I ran sysclean.com (in safe mode and system restore off) along with the
    latest pattern file and it did not detect anything using PC-Cillin. I no longer have this virus log.

    2. In safe mode with networking and system restore off: I did an online scan at
    Trend micro using housecall and it did not detect anything.

    3. In safe mode with networking and system restore off: I did an online scan at
    Symantec Security Check and it detected 9 infected
    files including the following: a) Adware.Gati in D:\codecs_and_player\DivX\Divx
    Pro codec\gain_trickler.exe b) downloader.trojan in new.exe c)
    Adware.BetterInternet in windows\phage2.exe d) Bloodhound.packed in
    windows\system32\cm.dll e) Backdoo.Tofger in windows\system32\paydial.exe f)
    Adware.CoolWebSearch in windows\system32\ppma.dll g) Adware.WhenU in
    windows\system32\WSN_MKTE0404Inst.exe h) Download.trojan in documents and
    settings\Administrator\LocalSetting\TemporaryInternetFiles\Content.IE5\8L6BCDAN\Sploit[1].anr
    i) Adware.BetterInternet in documents and
    settings\Administrator\LocalSettings\temp\phage2.exe

    3. In safe mode with networking and system restore off: I ran McAfee AVERT
    Stinger and it did not detect anything.

    4. I cleaned the hard drive, removed temporary internet files with CCleaner.

    5. Scanned machine with Ad-Aware SE with the Ad-Aware VX2 Cleaner plug-in and it
    did not detect anything critical.

    6. Scanned with Spybot with the Spybot DSO Exploit patch and it found Haxdoor-H.
    Under the Haxdoor-H heading there are 2 files including klogini.dll and
    draw32.dll. Although I selected "fix" it was only able to "fix" one of the
    files but both re-appeared upon re-boot and re-scan with spybot.

    7. I ran CWShredder, Kill2me, about:buster and HSremover. I ran these because at
    one point I had an about:search hijacker but I think it has been destroyed.

    8. Haxdoor-H still present so I scanned with Hijack this. Here is the log file:

    Logfile of HijackThis v1.99.1
    Scan saved at 11:57:20 PM, on 3/6/2005
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

    Edit by chaslang: Unrequested inline log removed


    Things that the computer is doing:

    1. Whenever I try to run a full PC-cillin scan the computer crashes and re-boots.

    2. PC-cillin is running without all the internet security setting that it
    usually does (i.e. no firewall and no Wi-Fi detection.

    3. While browsing, Internet Explorer will suddenly pop up with a message that a problem has been encountered (annoying pop-up that sends back report of encountered problems with IE to Microsoft). Clicking on "Don't Send" kills all internet windows.

    4. Also, comp will crash randomly when the control panel is accessed to "Add/Remove any programs" as well as when searching for files/folders.
     
    Last edited by a moderator: Mar 7, 2005
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You OS is severely out of date and so is your IE version. This presents a major security risk for you. You need to visit Windows Update and (if you do not want XP SP2) at least do a Custom scan and get all the required updates (other than SP2). Definitely do not try to update to SP2 if you have any malware issues.

    Note: You must have ALL browsers closed anytime you use HijackThis.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! It looks to me like you did pretty much everything from the READ.

    Please try the below steps:

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    O1 - Hosts: http://213.159.117.203/dkprogs/hosts.txt
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
    O20 - Winlogon Notify: draw32 - C:\WINDOWS\SYSTEM32\draw32.dll

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\SYSTEM32\draw32.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again.

    Now run Ccleaner

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  5. AVIS

    AVIS Private E-2

    Hi!

    Thanks for your reply. I was not able to delete C:\windows\system32\draw32.dll. I went to see if the file was read only but it wasn't (i.e. the read-only box was already unchecked. But i went ahead and did the other things that you asked me to do.

    I forgot to mention in my original post that during the AVAST scan, it was not able to scan c:\windows\system32\draw32.dll or c:\windows\system32\vtd_16.exe. Similarly, during my Bitdefender scan it identified many password protected files. I am not sure what the significance of this is so I will attach the Bitdefender log along with my most recent HJT log.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download: http://www.atribune.org/downloads/HSFix.zip

    Extract the tool from the ZIP File to a folder you can easily find (preferably in its own folder - like c:\HSFix). Then follow the procedure below:

    Boot to Safe Mode open the HSFix Tool folder and DoubleClick hsfix.bat and let it run. It will produce a log here - C:\hslog.txt

    Boot back to normal mode and post the hslog.txt file as an attachment.


     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ignore the Bitdefender lines, they are not problems.

    Also post a new HJT log after complete my previous message with HSFix Tool.
     
  8. AVIS

    AVIS Private E-2

    Here is the hslog.txt and the new HJT log after running hsfix.bat
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please boot to safe mode and run HSFix Tool again. Run it two times. Save the log each time and post them when you come back here again.

    Looks like the draw32.dll line is gone from the HJT log but the file could not be deleted last time.
     
  10. AVIS

    AVIS Private E-2

    I have attached the 2 HSFix logs. On the second one draw32.dll and
    vtd_16.exe were not detected. I re-ran spybot and it did not detect Haxdoor-H. Does this mean that the trojan has been deleted and that the computer is clean?
     

    Attached Files:

  11. PhilliePhan

    PhilliePhan Guest

    This is very likely the case. You should run a few IE sessions and then attach another HJT Log for Chaslang to review.

    If you think some Haxdoor remains (it is a persistent little bugger!) you can check out this thread and search your machine for the files I listed in post #28. (Don't do those steps, though! Just look for the baddies.)

    http://forums.majorgeeks.com/showthread.php?t=54566

    PP :)
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks for jumping in while I was out PP! Yes I agree! More than likely we go it. But I also agree it would be a good idea to "look" for the files mentioned in the link PP provided.

    If you do not have any of those files, it is time to get your OS and IE versions updated. You can do this and take other necessary steps to help protect youself by following the steps in the below thread:
    How to Protect yourself from malware!
     
  13. AVIS

    AVIS Private E-2

    Hi!

    Here is my HJT log. I went through the files in the post you suggested and I didn't find any of the files listed.

    Only one thing remains to be solved! My PC-cillin settings cannot be returned to normal! I cannot enable Wi-Fi detection or the personal firewall. Aside from that, the computer is not crashing and the IE explorer pop up has ceased!

    One question! I suppose that HJT is letting us know all the processes that are running? Its interesting because I downloaded process explorer but I could never find the names of files that would be running due to the virus. Anyways, after trying to fix the computer for 3 days myself I am SO glad I fell upon this site! You guys are terrific. Thanks so much for helping me! I will definetly update my system and make sure I am better equipped to prevent this from happening again!!
     

    Attached Files:

  14. AVIS

    AVIS Private E-2

    so I spoke too soon! I went back to double check all the files and this is what I found:

    [HKEY_Local_machine\SYSTEM\currentControlSet\ENUM\ROOT\LEGACY_MEMLOW

    although in the text of the link provided it was written as:
    [HKEY_Local_machine\currentControlSet\ENUM\ROOT\LEGACY_MEMLOW
    (I.E. no system)

    I also found c:\windows\system32\hm.sys
     
  15. AVIS

    AVIS Private E-2

    sorry...i tried to edit my post but it was too late!

    I also found:

    [HKEY_Local_machine\SYSTEM\CurrentControlSet\Control\SessionManager\MemoryManagement]
    Name = "EnforceWriteProtection" and the value in the data set was 0x00000000(0)
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! So you should go back to the thread that PP gave you and run the steps in message #28. There are steps there to remove those registry keys and a bunch more that could be present. It will not hurt you to follow all those steps. Obviously some of filenames from the link PP gave will not be the same as for your problem. Just ignore them.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds