My AVG Found a Trojan But Cannot Be Healed

Discussion in 'Malware Help (A Specialist Will Reply)' started by Global2004, Jul 16, 2006.

  1. Global2004

    Global2004 Private First Class

    Hello All,

    1) I have completed everything in the Read & Run Me First....

    2) My AVG has found a Trojan called: Trojan horse BackDoor.Generic2.CGZ
    Its "status" is Infected, Embedded object also Infected, Archive
    "Selected object is inside the archive and cannot be healed...

    3) I've included all my text files from scans except one. Panda ActiveScan could not be attached as I had met my 3 attachment limit on this post.

    4) Major concern last week. We leave our computer on and hooked up to the internet 24/7. We turned on the monitor one day and found five items open or changed.
    i) Internet Explorer was open and the address was: http: //badars.phpnet.us/ SpooIs.exe
    ii) Our control panel was open and Windows Firewall was hi-lighted.
    iii) A black DOS window was open and one line of text caught my eye. C:\WINDOWS>SpooIs.exe -install Access is denied. (I have screen shots of this)
    iv) Our AVG had been removed
    v) Our Skype name had been changed to something rude.

    The computer seems to be running fine right now and we disconnect from the internet whenever we are not on.

    4) Our computer is shared our children and they have a habit of downloading things when told not to. After our problem is fixed my wife and I would appreciated if any assistance could be given on how to set up accounts so they cannot download from the internet. Most likely solving most(one) of my headaches.

    Thank you in advance.
    Global:rolleyes:
     

    Attached Files:

    Last edited by a moderator: Jul 16, 2006
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All you needed to do was attach it in a second message. Please attach it.

    Dangerous idea especially if not properly protected.

    Did you install WinVNC to allow remote access? This could be how someone got into your PC. WinVNC is a valid program but not if you did not install it. And if you did install it, was it password protected???

    They should all be Restricted User Accounts. And make sure that ALL accounts are properly password protected (even the Administrator account that only shows in safe mode) and make sure that you must login (select a user account and enter a password) to get access to the PC. However I would change all of your Passwords now because they may have been compromised.

    You also should stop BitTorrent and other files sharing programs (if you have any) from loading at startup. You may have a worm named VBS.Kevor.Worm. It attempts to spread through the iMesh or KaZaA file-sharing networks

    You need to follow the directions in step 7 of the READ ME and not use MSconfig to control startups. Run MSconfig and select Normal Startup then exit MSconfig but do not reboot yet if it tells you it needs to.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\WINDOWS\ServiceDaemon.exe
    C:\WINDOWS\ssh.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - Startup: winboot.lnk = C:\WINDOWS\system32\dllcache\sp2\winboot.bat

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\system32\dllcache\sp2\winboot.bat
    C:\WINDOWS\ssh.exe
    C:\WINDOWS\system32\win.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  3. Global2004

    Global2004 Private First Class

    Hello Chaslang.

    The Panda Active Scan has been attached to this message.

    We did not install VNC, however the owner of the PC Service who built our computer installed it on our computer so that he could gain access whenever we called him with a problem. He would ask us for our IP address and then we could see him doing his work. I dont feel he would have been the one who hacked our computer.
    When clicking on options in VNC, the 'Authentication' tab is selected. VNC Password Authentication is selected. When I select 'Configure', the window 'VNC Server Password' comes up asking for Password and Confirm Password. I'm assuming I should fill in this Password window? When the PC Service needs access to our computer, will VNC tell me when to enter my password?

    I removed BitTorrent and Kazza through my Add or Remove Programs a little while back. I checked again tonight and it does not appear to be there.

    -I ran MSconfig and selected 'Normal Startup' and then exited. It asked if I would like to reboot. I selected reboot later.

    -I went in and made sure hidden files were enabled.

    -I ran HijackThis and clicked on Open the Misc Tools Section. I then selected Open process manager. I selected the processes you advised me of and was given the following message for each:

    The Selected process could not be killed. It may have already closed, or it may be protected by windows.
    This process might be a service, which you can stop from the Services applet in Admin Tools.
    (To load this window, click Start, Run and enter 'services.msc')

    -At this point I felt it didn't make any sense to continue on with the instructions you layed out for me until I informed you of what happened.

    Thanks,
    Global
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! You have it backwards. When your PC Service tries to run a VNC Client to connect to your PC (which is running as a server), they should be asked for a password. If you did not have this password protected, it is a big security risk as ANYONE could connect to you. You should have a password that you have chosen for when you want to allow the PC Service to connect and when you don't need service, change it to a different password.


    Just continue thru with ALL instructions. Neither of the message that HJT actually gave you are true.
     
  5. Global2004

    Global2004 Private First Class

    Hello Chaslang,

    I went through all the steps that you outlined for me. HijackThis still gave me the same message, "The Selected process could not be killed. It may have already closed, or it may be protected by windows.
    This process might be a service, which you can stop from the Services applet in Admin Tools.
    (To load this window, click Start, Run and enter 'services.msc')"

    I continued as you stated and fixed,
    O4 - Startup: winboot.lnk = C:\WINDOWS\system32\dllcache\sp2\winboot.bat

    I then went into safe mode and using Windows Explorer deleted, C:\WINDOWS\system32\dllcache\sp2\winboot.bat
    C:\WINDOWS\ssh.exe
    C:\WINDOWS\system32\win.exe

    Since I'm running XP, I deleted all the files in Prefetch and ran Ccleaner.

    I then reset my Web Settings in Explorer, using Major Geeks in the address.

    I then rebooted my computer into normal mode. A message came up when I rebooted. It is a System Configuration Utility window.

    "You have used the System Configuration Utility to make changes to the way Windows starts.

    The System Configuration Utility is currently in Diagnostic or Selective Startup mode, causing this message to be displayed and the utility to run everytime Windows starts.

    Choose the Normal Startup mode of the General Tab to start windows normally and undo the changes you made using the System Configuration Utility.

    Dont show this message or launch the System Configuration Utility when windows starts.
    OK"

    I have not touched this window or selected OK, because frankly I have no idea what I should do. I will wait to hear from you before I do anything and if possible could you point out the steps I will need to take for this.

    Things I have noticed are that my computer is running very very slow. Whenever I select an application, ie: open FireFox or AVG to update it can take anywhere from 10 to 45 seconds to open.

    One additional question, should I keep Counter Spy on my computer or should I remove it now?

    I will attach a new HijackThis log.

    Thanks again,
    Global
     

    Attached Files:

  6. Global2004

    Global2004 Private First Class

    Hello again Chaslang,

    In addition to my other post, I have encountered one other problem.

    When I went to check my email in Microsoft Outlook a "Outlook Send/Receive Progress" window was up. It was showing an error message.

    ! Task 'my email address - Sending and Receiving' reported error (0x8004210A) : 'The operation timed out waiting for a response from the receiving (POP) server. If you continue to receive this message, contact your server administrator or Internet service provider (ISP).'

    Would this have happened while we were doing our fixes? Any suggestions?

    Thanks
    Global
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is MSconfig which I mentioned in step 7 of the READ ME and it is something that we do not want you running. We wanted you to select Normal Startup like the message indicates. I already mentioned this in message number 2 but you did not follow those directions.

    Click Start, Run, and enter msconfig and click OK. Select Normal Startup and then reboot your PC.

    Yes you can uninstall CounterSpy now!

    Nothing we did should impact your email. You may need to just setup you email accounts incoming and/or outgoing pop3 server address.


    I will be on vacation until 7/31/06 . One of the other Mods or Admins here may be able to pickup where I leave off.
     
  8. Global2004

    Global2004 Private First Class

    Hello Chaslang,

    My apologies on missing step 2.

    I have now selected normal startup and rebooted my computer. I have also uninstalled Counter Spy. Things seem to be running a bit faster.

    Did you have a chance to look at my HijackThis log? Am I Malware free? My AVG still indicates that I have the same virus in my computer, (Trojan horse BackDoor.Generic2.CGZ) any suggestions?

    I really do appreciate all the help Major Geeks and its techs do to help people out. Thank you very much.

    Global

    Please enjoy your holidays.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Cannot answer that since you had MSconfig running. You would need to attach a new log now that you stopped it.

    It is not helpful to us unless you give file names and where it is being found. This could just be a matter of the fact that we have not run the final steps to toggle system restore as mention in step 1 of the READ ME. We only go back to this step when we have finished all of our cleaning. Until that point we don't care about what is being found in System Restore (if that is what AVG is finding).

    I suggest you do the below anyway because chances are you are pretty clean!

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    Now see if you are still getting messages from AVG.

    After that, you should work thru the below link:

    How to Protect yourself from malware!



    And now I really am on vacation! Thanks!
     
  10. Global2004

    Global2004 Private First Class

    Hello Chaslang,

    I do hope you enjoyed your holidays. I'm sure you need them from time to time to recharge your batteries after answering all of our questions.

    I will attach another log when I arrive home tonght.

    The Trojan horse BackDoor.Generic2.CGZ is no longer in AVG since I flushed the system restore points as you suggested.

    I have gone through the post on "How to protect yourself from Malware". I have a question regarding step 3) Firewall. I have a router on my computer, can I run one of the Firewall programs as suggested in section 3 along with my router? Of the five listed, which one would you suggest?

    Thanks again Chaslang and I will post that hijackthis log tonight.

    Global2004
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I assume you meant you have an external router which you use to connect your PC to the internet. Yes, you should still use one of the Software Firewalls. Newer router normally do contain a hardware firewall but a Software Firewall should still be used. I personally prefer ZoneAlarm.
     
  12. Global2004

    Global2004 Private First Class

    Hello Chaslang,

    Here is my updated Hijackthis log.

    Thanks for your help.
    Global
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I missed one item last time!

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to WinNT System Host ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    tcpsys

    If you receive any error messages just ignore them and continue.

    Now exit HJT and reboot when it tells you it needs to.
    After reboot, run Windows Explorer and delete the below file (if found, it may not be):
    c:\winnt\system32\taskgmr.exe <--- Be careful!!! DO NOT delete taskmgr.exe Note the spelling is gmr in the bad one.

    Now attach a new HJT log.
     
  14. Global2004

    Global2004 Private First Class

    I went through the steps you outlined in the previous post.

    After rebooting my computer, I ran Windows Explorer and looked for c:\winnt\system32\taskgmr.exe. It does not appear to be there as you suggested it might not.

    I have attached a new Hijackthis log to this post.

    *One additional question- I've read some of your suggestions to other people in other forums regarding some programs that run at startup and that some really dont need to start a startup. There are a few that start up when I boot my system that I would like to stop.

    1) Can you give me the steps on how to stop these programs at startup? ie) VNC
    2) Can these programs still be started only when I require them?

    Thanks again Chaslang. My wife and I really do appreciate the service you and Major Geeks provide.

    Cheers,
    Global
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you stop VNC from loading at startup, you could defeat the whole purpose of using it. If the PC ever resets due to power failure or another reason and it does not run at startup, you will not have remote access capability. Also there may be other features of VNC that will not work properly if the service does not run at startup.

    What other programs/processes are you thinking about not running at startup?
     
  16. Global2004

    Global2004 Private First Class

    Hello Chaslang,

    The only time I utilize VNC is when we contact our PC Service about a problem and then they hook in. Me or my wife never use it to get on the computer from off site. VNC also concened us as I mentioned earlier in the posts about seeing a hacker playing around on our computer. I just thought if it doesn't startup at reboot we'd be much safer.

    A couple of other programs I thought we could remove at startup are things like Skype, DVD43 and Daemon. Daemon was put on our system by the PC Service and I really dont understand it and have never used it.

    By the way, did that last HijackThis log check out?

    Again I just wanted to stress to you how much my wife and I appreciate all of your time and help you have given us. It seems to have been much more useful than the assistance we get from our PC Service.

    Cheers,
    Global
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then look in the options for VNC to see if it gives you the ability to not load it at startup. If it does, then use that option to disable or enable when needed. Otherwise, uninstall it to be completely safe.

    If they installed this stuff without your permission you should not be using them as a PC service. Uninstall ALL programs that you do not need.

    Yes the log was clean.

    You're welcome! Happy I could help! And I did not even need VNC! ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds