Haxdoor_H

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Nitrowing, Nov 30, 2004.

  1. Nitrowing

    Nitrowing Specialist

    Ths trojan is on my mates computer (hey - I got rid of the other 230 virii/trojans/worms that were on there!!!) and it's being a bitch.
    Adware, spybot, AVG, Trend Housecall have all been run multiple times and in different order.Currently scanning with RAVantivirus.

    Is there a tool to use for this virus?
     
  2. Kodo

    Kodo SNATCHSQUATCH

    Please follow all the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal


    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.
     
  3. Nitrowing

    Nitrowing Specialist

    Now, this is why I asked if there was a specific tool for this virus - I now have complete boot failure, not even safe mode. I'm sure 'Last known good' is going to re-install the files that some of those progs just got rid of... :(
     
  4. Kodo

    Kodo SNATCHSQUATCH

    if you had that much crap on your machine, chances are a specific tool would catch one specific item and I'll put money down that you had MUCH MUCH more on your system than you know. That is why we have people run our tutorial. It covers most of the ground with malware. It could just as well have been one of the pieces of malware that hosed your system. You might as well try LKG to get back up. Since you had such a large problem, we'll just go ahead and ask you to post a hijackthis log as explicity directed in this thread.
    Hijack This Tutorial And How To Post Your Log File
     
  5. Nitrowing

    Nitrowing Specialist

    Thanks Kodo - I've spent about 9 hours on my 'mates' pc (he's going to owe me a beer or 10!!) clearing out junk that wouldn't have been there with some basic pc knowledge...

    Here's the HJT log

    [log removed]
     
    Last edited by a moderator: Nov 30, 2004
  6. Kodo

    Kodo SNATCHSQUATCH

  7. Nitrowing

    Nitrowing Specialist

    Out of that log - I know that
    C:\WINDOWS\system32\vtd_16.exe is BAD - I have it disabled with zonealarm to stop it doing anything online.
    I don't know what these are
    C:\WINDOWS\system32\crypserv.exe
    C:\WINDOWS\system32\drivers\dcfssvc.exe

    Thanks for your help :)
     
  8. Nitrowing

    Nitrowing Specialist

    OOPS! I got the version of their website, not this one... and I'm CTRL+V mad...
     

    Attached Files:

  9. Kodo

    Kodo SNATCHSQUATCH

  10. Nitrowing

    Nitrowing Specialist

    Looking at this,Haxdoor H it seems I'm going to have to format C.
    Thanks for your help Kodo
     
  11. Kodo

    Kodo SNATCHSQUATCH

    I don't see anything where it says you need to reformat...
     
  12. Nitrowing

    Nitrowing Specialist

    The system wont boot in safe mode and only rarely boots normally - usually have to f8 and LKG.
     
  13. Kodo

    Kodo SNATCHSQUATCH

    there's always the option of yanking the drive and putting it another machine as a slave and scanning/cleaning that way. None of the malware would have init keys on that clean machine. Being more safe than sorry, I would put it in a machine that isn't critical.
     
  14. Nitrowing

    Nitrowing Specialist

    I did just that - put his hdd in my caddy and went file deleting/regediting.
    When I was doing this, AVG alerted me to another file in a hidden System Volume Information folder that had the virus.
    All deleted - all gone - my mate will be happy (until he sees the beer tab ;) )

    Thanks for all your help Kodo :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds