trojan-backdoor-bobax

Discussion in 'Malware Help (A Specialist Will Reply)' started by tkjdnow, Apr 2, 2007.

  1. tkjdnow

    tkjdnow Private E-2

    SpySweeper detected and quarantined what it titled trojan-backdoor-bobax March 21. SSweeper says that this trojan opens ports and rewrites code for complete remote control of a computer, and advises changing all passwords and bank account numbers. 2-3 days had passed since my last sweep with SS.

    Have followed all steps with these exceptions: could not run Bitdefender in safe mode with networking -- the computer could not detect wireless networks in safe mode, so I ran it in normal boot. Panda effectively froze--one file every minute or so, and after 9 hours I stopped the scan--also in normal mode.

    AdAware, SpyBot, Bitdefender, Windows Defender, AVG free 7.5.466, SpySweeper, and Ewido report 0 infected files.

    I am hoping you will check for suspicious code or other evidence of tampering, and tell me I really do not have to change bank account numbers.

    Also, since I am trying to stay offline, I have copied the three attached textfiles to the desktop of a friend's computer and uploaded from there.

    And, if it matters, after running the various cleaners and scans as owner then as administrator in safe mode, ( probably 6 re-starts in safe mode in all) the computer took exception to re-booting in safe mode again .... took 4 or 5 attempts for windows to recognize the command and not open in normal mode.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I believe Spy Sweeper had false positive detections related to that. Did you save a log? What detections version were you running at the time? What version do you have now?

    When did you download the versions of GetRunKey and ShowNew that you used? They are way out of date and do not show everything that current versions of the programs would show. You must always work from the current online copy of the READ ME.

    You should not be using Spybot's Teatimer per the READ & RUN ME instructions and in particular you should not be using it because you have Spy Sweeper running. You should disable Teatimer. Also you should uninstall the below to avoid conflicts with Spy Sweeper and excessive use of system resources.

    CounterSpy - we are finished with it anyway
    Windows Defender


    You should also have HJT fix the below line:
    O4 - HKLM\..\Run: [msci] C:\DOCUME~1\Owner\LOCALS~1\Temp\20051221174657_mcinfo.exe /insfin


    Other than the above and based on your outdated logs, you are clean.
     
  3. tkjdnow

    tkjdnow Private E-2

    Have uploaded shownew files. --used the old download in error, from trying not to go online, downloading to friend's computer, and copying to mine. They were from your site in Aug 06.

    Your site will not let me attach getrun. Says I have already done so. Tried to rename file as new getrun.txt and name.txt, and it still will not let me upload. Do you want it posted in the text of a message?
    Edit/Delete Message

    SpySweeper version is 5.3.2.2361, the most current, same as the one which found bobax. I can find no option in SpySweeper that shows logs or shows a history of past sweeps. I deleted the quarantine file before running HJT.

    HOW CAN YOU DISABLE Teatimer? I thought I did that last year. I have looked for actual instructions both here and at Spybot sites. Read and Run Me just says to do it.

    Thank you for your help. I know it is hard to deal with people who do not understand how to do basic stuff. I think I downloaded the trojan along with a movie trailer, from a link on a public forum.

    Does it matter that Add and Remove programs has incorrect dates for last used? Most recent date found was Feb 07.

    Thanks again.
     

    Attached Files:

    Last edited: Apr 6, 2007
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are still using a very OLD version. You need to download the current version and get a NEW log.


    That means you are not getting a new log. You are trying to attach the same old log and it also means you are still using the OLD version of the tool. Download the correct version and use it.

    Pretty simple! ;)
    • Run Spybot and click Mode
    • Select Advanced Mode.
    • Then click Tools and select Resident.
    • Now in the right window pane, uncheck TeaTimer.
    • Also while this is open, in the left column now select IE Tweaks
    • and then in the right pane make sure all the Miscellaneous locks are unchecked.
    • Now quit Spybot!

    No! It is often wrong!
     
  5. tkjdnow

    tkjdnow Private E-2

    attached are getrun and shownew txt files from your link in R&Rme, downloaded to my own program files. Have deleted all other versions.

    Have deleted the suggested entry in HJT log from 4/2.

    Have disabled TeaTimer.

    Have uninstalled Counterspy.

    Windows Defender still installed - why is it to be removed? It has found nothing bad yet, since Aug of 06, but neither has spybot. It did show me the file you referenced via HJT. Sent that info to Webroot thinking it might be bogus, but they did not respond to the notice.

    I will install Zone Alarm and disable or uninstall Defender as per your instructions.

    Should I go through the disable system restore procedure also?

    Thanks for your clear and timely responses.
     

    Attached Files:

  6. tkjdnow

    tkjdnow Private E-2

    Also--just ran avg 7.5 free and it reports 0 threats, but system32\ntoskrnl.exe and user32.dll as changed. These seem to be important files. Have not tried to restart in case I can't.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It took you to long to get the proper version of ShowNew! ;) Now you need to get the new version just released today. It may prove useful to us since it shows a lot more. Get a new log from the latest version.


    I said to uninstall it in message # 2 right after saying to uninstal CounterSpy.

    That O4 line was not malware. It was just a scan from McAfee that you don't need and since it was installed in a Temp folder, it was deleted long ago by any cleanup (including Ccleaner).


    Not yet! First tell me what (if any) malware issues you may be experiencing.
     
  8. tkjdnow

    tkjdnow Private E-2

    New newfiles uploaded. Did not uninstall Defender because it is my only firewall. Have read that ZoneAlarm has trouble with Mozilla. I am sharing a DSL connection whose router is in another building and I cannot access it to reboot if it malfunctions.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Windows Defender is not a firewall! It is a an antispyware program and you already have Spy Sweeper to do this (assuming Spy Sweeper is a paid version???? ) which is why I said to uninstall Windows Defender. You still need to uninstall it. And you should also remove Ewido! Only one antispyware realtime blocker should be used. This is similar in logic to only one antivirus program being used.

    ZoneAlarm (which you mentioned) is a firewall and I don't know of any problems with Mozilla. And do you mean Mozilla or do you mean Mozilla FireFox. That would be a topic for the Software Forum anyway. You do need a firewall!!!

    You are using this J2SE Runtime Environment 5.0 Update 11 which now an outdated version of Sun Java. You should have uninstalled it and upgraded per the instructions in step 6 of the READ & RUN ME.

    Are you having any malware problems? The only issues I have seen were your over use of antispyware programs!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds