Win32.BettInet.AR (Aurora)

Discussion in 'Malware Help (A Specialist Will Reply)' started by jj_bloodhound, Aug 7, 2005.

  1. jj_bloodhound

    jj_bloodhound Private E-2

    Greetings!

    I am attempting to rid my friend's laptop of Aurora and would be grateful for any help you could offer. I have read and followed all four of the Scanning and Cleaning steps on Major Attitude's How to: Spyware, Trojan And Virus Removal.

    Here is some additional information that may prove useful to you:

    Windows XP Home SP2 - fully updated after infection
    EZ Antivirus and Firewall - added after infection
    Webroot Spy Sweeper - added after infection

    Hijack This was downloaded but I have not ran it as of yet. I read somewhere on here that I am not to post it until asked.

    Thank you in advance for your help...
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do the below too!

    - download Nail/Bolder/Aurora Remover 0.3.1 Beta and save it to its own folder like c:\ABIremover

    - Now extract the abiremover.exe file from the ZIP file into the folder you created but do not run the EXE yet. We will run it later.

    - Now boot into safe mode, run the abiremover.exe but make sure you are physically disconnected from the internet (unplug your cable to be sure). Just click install, wait (explorer window will disapear)

    - When abiremover finishes just reboot into normal and continue with the below steps.


    Also download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    Let us know if this helps or not.
     
  3. jj_bloodhound

    jj_bloodhound Private E-2

    chaslang,

    First off, thanks for responding!

    I downloaded and ran the first program in safe mode and was not connected to the internet. Hoster was run in normal mode as requested but still no luck.

    Looking for more guidance. Thanks for taking the time to help.

    -jj
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Follow the below steps exactly as written:

    - Boot in normal mode

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  5. jj_bloodhound

    jj_bloodhound Private E-2

    Hey chaslang,

    I have ran Hijack This and attached the log file as requested.

    Awaiting further instruction from you. As always, thanks for your help.

    -jj
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note: You may run into problems doing the below unless you disable or uninstall SpySweeper because it will see these attempted changes and may tyr to block them. In most cases though, you can just tell it to accept the change.

    Is there a reason why you did not run the BitDefender online scan?

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.

    c:\windows\system32\hpexgfg.exe
    C:\WINDOWS\System32\?ttrib.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
    O2 - BHO: SDWin32 Class - {134AEAB8-CE10-4D3C-8D93-97C0107DDEE5} - C:\WINDOWS\System32\dqltt.dll
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {BACBA8F6-4465-4FB1-4361-69534E815D90} - C:\WINDOWS\System32\kcmpp.dll (file missing)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O3 - Toolbar: (no name) - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - (no file)
    O4 - HKLM\..\Run: [q77Q36h] cresccp.exe
    O4 - HKLM\..\Run: [Ioxx] C:\WINDOWS\Bxdp.exe
    O4 - HKLM\..\Run: [lchnkw] c:\windows\system32\hpexgfg.exe r
    O4 - HKCU\..\Run: [Ikcsxqx] C:\WINDOWS\System32\?ttrib.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\Bxdp.exe
    C:\WINDOWS\System32\dqltt.dll
    c:\windows\system32\cresccp.exe
    c:\windows\system32\hpexgfg.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Also look for and delete: C:\WINDOWS\System32\?ttrib.exe
    This is not to be confused with attrib.exe which is legitimate. Look for a file (the ? may or may not show) that has some characters at the beginning and ends with ttrib.exe. It is probably several 100k bytes in size which is much larger than the valid attrib.exe.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  7. jj_bloodhound

    jj_bloodhound Private E-2

    Hey chaslang,

    Strangely enough I ran the BitDefender online scan in safe mode as per the tutorial. I don't know why it didn't register.

    I followed your instructions and haven't seen anymore problems. EZ Firewall has not noticed any more outbound connections for Aurora or 0ttrib.exe which of course is a good thing. ;) However, not all the items you asked me to delete were available or found.

    For example, the C:\WINDOWS\System32\?ttrib.exe was no where to be found. A file named Ikcsxqx.exe with the Aurora icon was located in my search and I deleted it. It was cross referenced with the list of items to delete in Hijack This.

    For dqltt.dll, the file was not present but some XML data files were. They were listed as dqltta.xml (41 kb) and dqltte.xml (1 kb). They are still present on the system. Should I delete these files?

    I have attached the hijackthis log for your review.

    Two asides:

    How did you gain so much knowledge on this subject?

    and

    Is there any way that I can donate some cash for helping me out via PayPal?

    Cheers,

    -jj
     

    Attached Files:

    Last edited: Aug 8, 2005
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's because of two reasons:
    1) HJT deleted some of the files already when it fixed the entries.
    2) Sometime the files mutate (rename themselves) . This happen to you because one of the baddies is now:


    c:\windows\system32\wioefat.exe
    O4 - HKLM\..\Run: [ffpnybp] c:\windows\system32\wioefat.exe r

    You need to kill that process and fix the line with HJT then delete the file in safe mode.

    Yes!


    Years of using and building PCs! I use many PCs for my work too. Lot's of reading.


    Not that way but you could buy an MG's teeshirt or other items. Also send your friends here.
     
  9. jj_bloodhound

    jj_bloodhound Private E-2

    Hey chaslang,

    I think, with a tremendous amount of your help, we have Aurora beat. What a nasty little beast Aurora is. Judging by the posts it infects a large number of people.

    I figured that you've poured over many a book and manual in your day.

    I'll be sure to buy some swag and send them here. ;)

    Would you like me to post one final hjt log to make sure it's gone?

    Thanks again for the much needed help and advice.

    Cheers,

    -jj
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! And yes, post another log. Entries like:

    O4 - HKLM\..\Run: [ffpnybp] c:\windows\system32\wioefat.exe r

    have a nasty habit of coming back over and over again and renaming themselves each time. Sometimes there are other hidden files that need to be found and deleted to finalize the fix. This particular item is not part of Aurora.
     
  11. jj_bloodhound

    jj_bloodhound Private E-2

    Hey Chaslang,

    Here's what I hope to be my final hjt log file. Thanks for taking a look. :)

    Cheers,

    -jj
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  13. jj_bloodhound

    jj_bloodhound Private E-2

    You Rock, chaslang!

    You have my and my friends gratitude for your altruism. :)

    A number of my friends and aquaintences know that I do freelance web design. For whatever reason they assume that I can do everything with a computer. And while I can get a system fairly clean, Aurora was clearly more than a match for me. I'm sure that sometime down the road another friend will ask for help and, in turn, I'll be on here asking for your help. Thanks in advance.

    If you ever need help with a cascading style sheet, xhtml, 508 compliance or something else web related I'll do my best to help. Gratis, of course. ;)

    Time for me to quit monopolizing your time and finish by reading your article and purchasing a Major Geeks T-shirt at the online shop.

    Until the next time...

    Cheers,

    -jj
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds