Stopping Remote Access - Help Would Be Appreciated

Discussion in 'Malware Help (A Specialist Will Reply)' started by scooterd, Jun 16, 2006.

  1. scooterd

    scooterd Private E-2

    Hello,

    Using Windows XP on a fairly new Toshiba notebook, which appeared to have someone accessing the computer remotely, through it's built-in (factory installed) wireless card.

    In addition, we have found odd instances such as IE web page history listing web pages we haven't been to, have had notepad documents popping up on the desktop which we have not composed, and printers being added and printer icons being duplicated on our status bar. There have also been suspicious entries and reports found in Quickbooks.

    I have since disabled the card (as it's not needed) and have done all the things required (ran all the requested cleaners, utilities and anti-virus programs) before sending our HijackThis log, which is attached.

    Now for the final step and fine tuning, I would appreciate if someone could please check out the HijackThis log and guide me on how to best remove any other traces of potentially harmful items, as we feel there may still be traces of things that would allow someone (unauthorized) to communicate with this computer through our cable (ISP) connection. I am also attaching our PandaScan report.

    Thanks very much for any help that you could offer!

    S.D.



    computer
     

    Attached Files:

    Last edited: Jun 16, 2006
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach your Bitdefender log. Was it clean?


    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [LanzarT2006] "C:\DOCUME~1\NOONEE~1\LOCALS~1\Temp\{D31D3A67-2618-4AFC-90A0-CF14105F1B90}\{98032D6F-3EE6-4646-B68C-40BF012AC89B}\..\..\T2006tmp\Install.exe" /SETUP:"/l0x0009"
    O4 - HKLM\..\Run: [LanzarP2006] "C:\DOCUME~1\NOONEE~1\LOCALS~1\Temp\{B00EBE9A-563F-4FED-A879-609E66027A4D}\{EEBA9416-3207-47E0-9022-116440599DBC}\..\..\P2006tmp\Install.exe" /SETUP:"/l0x0009"

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Documents and Settings\NOONEE~1\Local Settings\Temp <--- delete all files in this Temp folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    You do have one other issue though. You have the below running from Panda Antivirus but you appear to be using Symantec. You should uninstall all of Panda.

     
  3. scooterd

    scooterd Private E-2

    Hello,

    Yes, my bitdeffender run had come back clean (no problems were detected) , I'll do the things you suggested.

    Again, thanks very much and I'll and post a new HT log soon.

    :)
     
  4. scooterd

    scooterd Private E-2

    Hi,

    I did everything requested, less the notes (and comments) below.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [LanzarT2006] "C:\DOCUME~1\NOONEE~1\LOCALS~1\Temp\{D31D3A67-2618-4AFC-90A0-CF14105F1B90}\{98032D6F-3EE6-4646-B68C-40BF012AC89B}\..\..\T2006tmp\Install.exe" /SETUP:"/l0x0009"
    (the listing mentioned above was no longer there, so I / HJT couldn't remove it)

    O4 - HKLM\..\Run: [LanzarP2006] "C:\DOCUME~1\NOONEE~1\LOCALS~1\Temp\{B00EBE9A-563F-4FED-A879-609E66027A4D}\{EEBA9416-3207-47E0-9022-116440599DBC}\..\..\P2006tmp\Install.exe" /SETUP:"/l0x0009"
    (this one was there, so HJT successfully removed it)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Documents and Settings\NOONEE~1\Local Settings\Temp <--- delete all files in this Temp folder
    "SQL" (in there) gave me a hard time removing, then it also came back (even though it was not read only)

    Make sure you tell me how things are working now.
    All in all seems better, but the fact that that SQL is there (I don't know why) and wouldn't let me keep it deleted, has me a bit concerned.

    New HJT log attached and your help is stilll greatly appreciated! ;-)
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why are you installing new applications while we are trying to fix your PC??????

    Earlier you had a Symantec Security Suite running and now you have installed CA\eTrust Internet Security Suite and have not correctly uninstalled Symantec first. You have the below service from Symantec still running.

    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
     
  6. scooterd

    scooterd Private E-2

    Very sorry. We wanted to get rid of Symantec because we really hated it and also felt it had let us down. CA\eTrust was available from our ISP (cable) and we thought the change would be good. The new anti-virus program had actually attempted to uninstall Norton first, so I guess it didn't do it rightI let (please forgive ;-)

    Also, the computer seemed to be running a little slow while online (maybe it was partially because that Symantec service was still running?)

    I have since attempted to remove all traces and mentions of Symantec.

    A new HJT log is attached, and thanks again for ALL your help!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may not see any improvement in speed from replacing Symantec with CA\eTrust Internet Security Suite . From what I have seen here from users thus far, it has bee a resource hog too. Maybe not as bad as Symantec but still a hog.

    Still has a component remaining. You can try to have HJT just fix the below line:

    O23 - Service: SymWMI Service (SymWSC) - Unknown owner - (no file)

    If it tells you it cannot fix it. We will need to use a different method. Let me know the results.
     
  8. scooterd

    scooterd Private E-2

    HJT wouldn't remove it, now was I able to remove it through deleting all instances or mentions of it in the registry. What method do you suggest I try, and any idea why that SQL log file is still showing up under that Local/temp area? (I don't know why it... "SQL" exists at all in there, or what it may have been / or is associated to?)

    Thanks again and I FYI, got your e-mail/file, and will follow up on it ;-

    Oh yeah... latest HJT log attached.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The normal procedure to handle removing of services (that is what the O23 lines are). Is to stop and then disable the service. And then you can delete the service. Editing the registry manually can cause problems, especially if you mess up and remove the wrong thing. Below I will post how that procedure would normally have been performed. It may or may not work exactly as expected now since you have been doing some manual changes. Give it a try and let's see what happens.
    No not really. Do you use any SQL applications? If so, they are just using that folder as a Temp folder like many other applications do. What is the file name?



    .
     
  10. scooterd

    scooterd Private E-2

    I removed that NT service (and exited HJT and ;left the computer running, haven't let it reboot, as you instructed)

    Do you use any SQL applications? If so, they are just using that folder as a Temp folder like many other applications do. What is the file name?

    I don't think I use any SQL apps. (I do use Quickbooks, but I don't "think" is uses SQL)

    File name (in Local\Temp) is simply "SQL" (and is a 0 byte text file)

    .[/QUOTE]

    What's next boss? ;-)
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member



    If you check a new HJT log is the O23 line gone?

    I don't know if Quickbooks uses SQL. Are saying it has no file extension (the characters that appear after a period is the extension. Like explorer.exe, the .exe is the extension.) If you right click the file can you get Properties and Version info?
     
  12. scooterd

    scooterd Private E-2

    023 entry is now gone, and file is actually SQL.log (computer was set to hide extentions for known file types, which I since unchecked).

    Aside from that, how are we looking (so far) and what else is recommended (I still haven't rebooted either).

    I'm not sure, but I get the impression that someone was in this system via a wireless connection (which I since disbled), and want to be sure we keep the bad guys out, as I am helping out a friend with this ;-)
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That was step 2 in the READ ME! ;)

    Your clean and you can reboot anytime now. I don't think the SQL.log has anything to do with malware. It could be related to Quickbooks based on some searching but I really don't know that for sure. But either way, it is not a malware problem to be concerned with.

    Encryption must be enabled (WEP keys) and the router should be password protected.


    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds