Help with Trojan Backdoor-AWQ removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by dngrsdv1, Dec 10, 2007.

  1. dngrsdv1

    dngrsdv1 Private E-2

    Please help!I have a nasty back door Trojan that locks up my system and does not even allow me to access the internet. I even had to borrow a friends laptop to be able to try and research a solution. I am trying to get together the necessary reports to see if maybe someone can steer me in the right direction but my system keeps locking up because of infection,
     
    Last edited: Dec 10, 2007
  2. abri

    abri MajorGeek

    Hi dngrsdv1!
    Welcome to Major Geeks

    See if you can get Combofix and AVG Antispyware to run and CCleaner. You may be able to transfer Combofix and CCleaner from another computer with a cd or flashdrive and run them in SafeMode.. If you can do any of these, try then to install the MGTools.exe file (also possible by downloading to another computer) onto your computer (in the root drive) and run it so we can see your logs.

    abri
     
  3. dngrsdv1

    dngrsdv1 Private E-2

    I was at my wits end and after doing a little research I took a chance and deleted file that was in question which was C:/program files/common files/microsoft shared/speech/wap64.dll. I'm not sure I'm out of the woods yet but I have regained the ability to access the web and not lock up. I have run all the cleaning procedures you recommend. I will attach my log files to see if maybe there is something detectable
     

    Attached Files:

  4. abri

    abri MajorGeek

    Hi dngrsdv!

    1)You need to uninstall the below:

    - Viewpoint Media Player
    - Java 2 Runtime Environment, SE v1.4.2


    2) Reboot after uninstalling the above.

    3) Now install the current version of Sun Java from: Sun Java Runtime Environment


    4) Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    5) Run HijackThis and select Do a system scan only. Select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [C:\WINDOWS\system32\V0330Cvw.dll] C:\WINDOWS\system32\RegSvr32.exe /s C:\WINDOWS\system32\V0330Cvw.dll
    O20 - Winlogon Notify: winmbj32 - winmbj32.dll (file missing)
    O23 - Service: Network Connection Manager (NetCM) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\Speech\svchost.exe (file missing)


    Do you know what this is? If not, please fix it as well. (do not click on the link)

    O16 - DPF: {97B79133-88F0-45F0-8D57-0F2EF27D9C66} - http://85.255.114.166/1/rdgUS2404.exe


    After clicking Fix, exit HJT.

    6) Now run CCleaner. Run the MGtools.exe file under C:\ and attach a fresh set of logs called MGlogs.zip with your next post.

    abri
     
  5. dngrsdv1

    dngrsdv1 Private E-2

    Abri,

    I appreciate all the help and prompt responses to my posts. I did as you instructed. I went ahead and deleted that strange line as well for I had no idea what it was. Here is my new MGlogs.zip file for you to inspect.
     

    Attached Files:

  6. abri

    abri MajorGeek

    Hi dngrsdv1
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Network Connection Manager
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT (it will now be called analyse.exe and you will find it inside the MGTools folder of your root drive), but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste NetCMinto the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Now run HJT/analyse.exe (select Do a system scan only) and select the following lines but DO NOT CLICK FIXuntil you exit all browser sessions including the one you are reading in right now!!

    O23 - Service: Network Connection Manager (NetCM) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\Speech\svchost.exe (file missing)

    After clicking Fix, exit HJT.

    Please run CCleaner and then rerun MGTools.exe (located directly under C:\ ) and attach a fresh set of Mglogs.zip (located in the MGTools folder) to your next post. I hope this will be everything.

    abri
     
  7. dngrsdv1

    dngrsdv1 Private E-2

    I went ahead and disabled that particular service though when I went to its properties it was already stopped. when I ran the system scan I didn't see that line in the list. here the logfile. Thanks again for the help!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do the below!!!

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Then reboot!

    After reboot, run MSconfig and select Normal Startup mode as was requested in the READ ME. Then reboot one more time.

    After doing the above, please download the current version of MGtools.exe to C:\ like you previously did. It was just updated. Then run MGtools.exe which will create a new C:\MGlogs.zip file. Please attach this new log file.
     
  9. dngrsdv1

    dngrsdv1 Private E-2

    Did as you requested. I'm not sure if this is a problem but I keep getting an error message as if I don't have administrator privileges when I change the startup. It does work but I don't remember getting this message before. I will attach it as well along with my log.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall ewido security suite it was discontinued and replaced by AVG Antispyware a long time ago.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
    O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now delete the below file if found:
    C:\WINDOWS\system32\ot.ico

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created

    Make sure you tell me how things are working now!
     
  11. dngrsdv1

    dngrsdv1 Private E-2

    Ok here goes. I can see that my systems is running so much better. You don't know how much I appreciate all you've been helping me with!:major
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You logs are clean but it appears that something blocking fixing of the below:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway

    It could be from Ad-Watch, McAfee or you may not have shutdown browsers before fixing. They are not big issues to worry about. You could just try again after shutting down Ad-Watch.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  13. dngrsdv1

    dngrsdv1 Private E-2

    I tried it once again with adwatch turned off but after I scanned again it was back. Oh well, its not that big a deal. My computer has come such a long way thanks to you guys. I'm sure we'll be in touch again the next time I kill my computer again. Your help was greatly appreciated.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds