Win32.Heur/backdoor64/ has taken over.

Discussion in 'Malware Help (A Specialist Will Reply)' started by ccn, Aug 31, 2013.

  1. ccn

    ccn Private E-2

    Hi folks, i somehow found the above nasty on my system and it has not allowed me to update and keeps shutting down my AV . I am in safe mode because my computer is inoperable in reg mode.






    I will gladly wait my turn and thank you so much for your help.

    I should add i recently re installed twice to no avail.

    Thanks for any help
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What exactly havppens when you try to boot in normal mode?
    There are no problems showing in your safe boot mode logs?

    Please empty your Recyle Bin which has lots of file showing in it.
     
  3. ccn

    ccn Private E-2

    Thanks for your assistance Chaslang, i have noticed exactly what you have regarding the recycle bin , no matter how many times i empty it the files come back.

    I can boot into normal mode but almost right away everything freezes and doesn't respond, AV's are turned off and despite constant attempts to turn on it's a futile effort.

    I should also note that this nasty has hidden behind password protected files which despite running Kaspersky virus removal tool and Bitdefender scanners (as on demand scanners only) both have failed to be of help but do reveal locked files.

    I attached an example from Kaspersky .
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is nothing of interest in that log and note if you are going to run Kaspersky, you really should uninstall Avast first.

    Try the below.

    Please do the below so that we can boot to System Recovery Options to run a scan.

    For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.


    Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
    Last edited: Sep 1, 2013
  5. ccn

    ccn Private E-2

    Here is the Farbar results.

    I should note that i downloaded Kasperskys tool before i posted last to show logs only. I have attempted to use Kasperskys Internet Security because it, and AVG is the only AV programs that have detected the Heur virus.

    Unfortunately that nasty continues to shut Kaspersky down every time, so i removed Kaspersky and downloaded Avast to at least provide some protection but Avast doesn't detect it.

    I know for sure it is behind those password protected files because it said Heur/backdoor/64.
     

    Attached Files:

    Last edited: Sep 1, 2013
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Per your FRST log, Kaspersky is not uninstalled.

    Also there is no malware showing. I suggest that you uninstall ALL protection type software including all of the below:

    Avast
    Kaspersky
    Malwarebytes
    SuperAntiSpyware

    Then reboot your PC. After reboot run the below FRST fix which will additional force out left over drivers/services from these and will delete folder to make sure they are gone.


    Download this >> View attachment fixlist.txt



    Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.
    Now reboot back into the System Recovery Options as you did previously.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now see if you can boot into normal Windows.
     
    Last edited: Sep 2, 2013
  7. ccn

    ccn Private E-2

    I uninstalled all security, the Kaspersky program was their virus removal tool only, not Kasperskys internet security with real time protection, that's why i installed Avast.

    I can boot into normal mode , let me know when i can re install security , the problem was never "can i boot into normal mode" it's the severe lack of programs responding and freezing that is the issue, and a complete shutdown of updating of programs.
     

    Attached Files:

    • .1.txt
      File size:
      9.7 KB
      Views:
      5
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the new log I requested not the fix that I gave you.

    Also you should run MGtools in normal boot mode now and attach the new MGlogs.zip file. That is if you can get it to run in normal boot mode.
     
    Last edited: Sep 2, 2013
  9. ccn

    ccn Private E-2

    Started to run MG tools in normal mode with UAC turned off but i'm getting what i usually get, non responding program.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That was explained in the black command prompt window. Take a look. ;)
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still never attached the fixlist.txt log I requested from running the FRST fix. You now just attached a new scan log. And you will notice that Kaspersky is still showing up. Also you will notice that you have not been running FRST from the Recovery Environment as requested. You are running it in normal boot mode from here C:\Users\patrick\Downloads\New folder which is not what was requested.
     
  12. ccn

    ccn Private E-2

    Seems the virus has shut down my admin rights now and my keyboard no longer works(i am using another computer) i can't post those logs as recovery console is not recognizing my flash drive. Everything seems to have stopped responding.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm sorry but there has been no signs of an infection in any of the logs you had attached thus far. The only problem I say was too many drivers and services due to multiple AV/AS products. If you can borrow a Windows Boot DVD from someone, perhaps you can get in the System Recovery Options with it and use System Restore.
     
  14. ccn

    ccn Private E-2

    Don't feel bad, i thought i would give it a shot. I had this thing a few years back and it was hell , it disguises itself constantly and thats what makes it so tough to pinpoint .

    Nearly all security consultants i talked to about it said it must be removed manually and thats if you can find it. The files i am seeing now are completely nuts lol.

    Rogue killer detected three infected items when i ran it at the beginning of this thread and Hitman Pro found 37 infected objects under threats not traces .

    What a nightmare, thanks Chaslang for your efforts regardless.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We fix them many times per week. Your logs do not show the infection.

    No. Your RogueKiller log had no problems. Those are Kaspersky drivers. The Hitman Pro log you attached found nothing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds