Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Removing backdoor trojans?
   
BullGuard Antivirus Forum > Virus Removal > Removal Tools > Removing backdoor trojans?  
Forum Quick Jump
 
New Topic Post reply to : Removing backdoor trojans? Printable version of : Removing backdoor trojans?
[ << Previous Thread | Next Thread >> ]

schmit
New Member


Date Joined Nov 2004
Total Posts : 4
 
   Posted 11-11-2004 6:01 (GMT +1)    Quote: Removing backdoor trojans?Alert an admin about: Removing backdoor trojans?
Hey,
 
Having some probs getting rid of some system32 backdoor trojans, there are also some strangle files that i'm not sure should be there e.g. winworld, spools, svphost etc.
 
Any help much appreciated.
 
Hijackthis log below.
 
Logfile of HijackThis v1.97.7
Scan saved at 16:50:26, on 11/11/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\BullGuard\BullGuard Communicator\xcommsvr.exe
C:\Program Files\Common Files\BullGuard\BullGuard Scan Server\bdss.exe
C:\Program Files\BullGuard\vsserv.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\sstray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\DOCUME~1\adam\LOCALS~1\Temp\1D.tmp.exe
C:\Program Files\BullGuard\bdmcon.exe
C:\Program Files\BullGuard\bgnewsag.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\svphost.exe
C:\Program Files\OpenOffice.org1.1.3\program\soffice.exe
C:\Program Files\blueyonder IST\bin\mpbtn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\adam\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.blueyonder.co.uk/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://192.168.100.1/config.html
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Print Spooler] spools.exe
O4 - HKLM\..\Run: [[Ephemeral 2.5] by TreeHugger, ] C:\DOCUME~1\adam\LOCALS~1\Temp\1D.tmp.exe
O4 - HKLM\..\Run: [BDMCon] C:\Program Files\BullGuard\\bdmcon.exe
O4 - HKLM\..\Run: [BGNewsAgent] C:\Program Files\BullGuard\bgnewsag.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\RunServices: [Print Spooler] spools.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [svphost.exe] C:\WINDOWS\system32\svphost.exe
O4 - Startup: OpenOffice.org 1.1.3.lnk = C:\Program Files\OpenOffice.org1.1.3\program\quickstart.exe
O4 - Global Startup: blueyonder Instant Support Tool.lnk = C:\Program Files\blueyonder IST\bin\matcli.exe
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
 
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16319
 
   Posted 11-12-2004 12:41 (GMT +1)    Quote: Removing backdoor trojans?Alert an admin about: Removing backdoor trojans?
Heycool
Download this scanner:
Activate all-Scan.
 
Get a newer Hijackthis, and post new logfile: http://danborg.org/spy/HJT/hijackthis.exe



Touch
Back to Top
 

schmit
New Member


Date Joined Nov 2004
Total Posts : 4
 
   Posted 11-13-2004 12:51 (GMT +1)    Quote: Removing backdoor trojans?Alert an admin about: Removing backdoor trojans?
hey touch,

I have scanned and downloaded new hijackthis, new file below

Bullguard is telling me they the backdoor trojans are in system volume, i also have a sasser worm too freaked

Thanks again in advance.

Logfile of HijackThis v1.98.2
Scan saved at 23:43:45, on 12/11/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\sstray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\DOCUME~1\adam\LOCALS~1\Temp\1D.tmp.exe
C:\Program Files\BullGuard\bgnewsag.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\svphost.exe
C:\Program Files\OpenOffice.org1.1.3\program\soffice.exe
C:\Program Files\blueyonder IST\bin\mpbtn.exe
C:\Program Files\Common Files\BullGuard\BullGuard Communicator\xcommsvr.exe
C:\Program Files\Common Files\BullGuard\BullGuard Scan Server\bdss.exe
c:\program files\bullguard\bdmcon.exe
C:\Program Files\BullGuard\vsserv.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\adam\Desktop\hijackthis-1.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.blueyonder.co.uk/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://192.168.100.1/config.html
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [[Ephemeral 2.5] by TreeHugger, ] C:\DOCUME~1\adam\LOCALS~1\Temp\1D.tmp.exe
O4 - HKLM\..\Run: [BDMCon] C:\Program Files\BullGuard\\bdmcon.exe
O4 - HKLM\..\Run: [BGNewsAgent] c:\program files\bullguard\bgnewsag.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [svphost.exe] C:\WINDOWS\system32\svphost.exe
O4 - Startup: OpenOffice.org 1.1.3.lnk = C:\Program Files\OpenOffice.org1.1.3\program\quickstart.exe
O4 - Global Startup: blueyonder Instant Support Tool.lnk = C:\Program Files\blueyonder IST\bin\matcli.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16319
 
   Posted 11-13-2004 10:12 (GMT +1)    Quote: Removing backdoor trojans?Alert an admin about: Removing backdoor trojans?
Download Killbox: http://www.downloads.subratam.org/KillBox.zip
Extract it from the zip file then double-click on Killbox.exe to run it.
 
Select the Delete on reboot option.
 
In the 'Full Path of File to Delete' box, copy and paste the following, clicking the 'Delete File' button (red circle with a white X) after pasting:
 
C:\WINDOWS\System32\SVPHOST.EXE
 
It will prompt you to reboot, do so.
 
After restarting, with only HijackThis running, scan and when complete, remove the following entry by checking the box to the left and clicking 'fixed checked':
 
O4 - HKCU\..\Run: [svphost.exe] C:\WINDOWS\system32\svphost.exe
 

Reboot again  when done,
------------------------------------------------------------
Go to task manager – ctrl+alt+del, and find if present:
1D.tmp.exe
 
Rightclick on it-end proces
 
Scan with Hijacktis, close all other windows, put a checkmark to these, and fix:
O4 - HKLM\..\Run: [[Ephemeral 2.5] by TreeHugger, ] C:\DOCUME~1\adam\LOCALS~1\Temp\1D.tmp.exe
Show hidden files:
 http://www.xtra.co.nz/help/0,,4155-1916458,00.html=
 
Reboot into Safe Mode (hit F8 key until menu shows up).
Find and delete:
C:\DOCUME~1\adam\LOCALS~1\Temp\1D.tmp.exe

Reboot.
Disable System Restore
 
Reboot,enable system restore.
 
post new log file. Stille have Sasser and trojans?
 
 


Touch
Back to Top
 

schmit
New Member


Date Joined Nov 2004
Total Posts : 4
 
   Posted 11-13-2004 1:45 (GMT +1)    Quote: Removing backdoor trojans?Alert an admin about: Removing backdoor trojans?
Hi Touch,

Followed your instructions 1d.temp.exe thing now doesn't appear to run in task manager or the temp file where i deleted it from but it is still in the hijackthis log even after i have checked it for deletion???

Anyway here is my new log:

Logfile of HijackThis v1.98.2
Scan saved at 12:39:10, on 13/11/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\sstray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\BullGuard\bdmcon.exe
C:\Program Files\BullGuard\bgnewsag.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\OpenOffice.org1.1.3\program\soffice.exe
C:\Program Files\blueyonder IST\bin\mpbtn.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Common Files\BullGuard\BullGuard Communicator\xcommsvr.exe
C:\Program Files\Common Files\BullGuard\BullGuard Scan Server\bdss.exe
C:\Program Files\BullGuard\vsserv.exe
C:\Documents and Settings\adam\Desktop\hijackthis-1.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.blueyonder.co.uk/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://192.168.100.1/config.html
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [[Ephemeral 2.5] by TreeHugger, ] C:\DOCUME~1\adam\LOCALS~1\Temp\1D.tmp.exe
O4 - HKLM\..\Run: [BDMCon] C:\Program Files\BullGuard\\bdmcon.exe
O4 - HKLM\..\Run: [BGNewsAgent] C:\Program Files\BullGuard\bgnewsag.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: OpenOffice.org 1.1.3.lnk = C:\Program Files\OpenOffice.org1.1.3\program\quickstart.exe
O4 - Global Startup: blueyonder Instant Support Tool.lnk = C:\Program Files\blueyonder IST\bin\matcli.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

thanks again for your help
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16319
 
   Posted 11-13-2004 2:15 (GMT +1)    Quote: Removing backdoor trojans?Alert an admin about: Removing backdoor trojans?
Ok, this re-occurring entry is part of the W32/Lemoor-A virus.  I hoped we could do it the easy way;-)
 
We need to manually remove this entry from the registry while disconnected from the internet. First print out these instructions or save them in a text file so you can reference them while the internet is down. Then disconnect your system from the internet (physically unplug it). Reboot your system (leave unconnected from the internet).
 
When back up, click on Start -> Run -> type in REGEDIT and hit the "Enter" key. When the Registry Editor opens up, navigate to this Folder (on the left hand side of the window) under the HKEY_LOCAL_MACHINE entry:
 
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
 
Then find this key in the right hand side of the window:
 
[[Ephemeral 2.5] by TreeHugger, ] C:\DOCUME~1\adam\LOCALS~1\Temp\1D.tmp.exe
 

Highlight the key and delete it. Then exit the registry editor. Run "Hijack This!" and verify that the entry is no longer there. Re-connect your system to the internet, then reboot once more. Once back up, run "Hijack This!" and post a new log so I can verify that the entry is gone as well.


Touch
Back to Top
 

schmit
New Member


Date Joined Nov 2004
Total Posts : 4
 
   Posted 11-13-2004 11:52 (GMT +1)    Quote: Removing backdoor trojans?Alert an admin about: Removing backdoor trojans?
Hi Touch,

I have deleted that entry from the registry. New log below:

Logfile of HijackThis v1.98.2
Scan saved at 22:42:10, on 13/11/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\sstray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\BullGuard\bdmcon.exe
C:\Program Files\BullGuard\bgnewsag.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\OpenOffice.org1.1.3\program\soffice.exe
C:\Program Files\blueyonder IST\bin\mpbtn.exe
C:\Program Files\Common Files\BullGuard\BullGuard Communicator\xcommsvr.exe
C:\Program Files\Common Files\BullGuard\BullGuard Scan Server\bdss.exe
C:\Program Files\BullGuard\vsserv.exe
C:\Documents and Settings\adam\Desktop\hijackthis-1.exe
C:\WINDOWS\system32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.blueyonder.co.uk/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://192.168.100.1/config.html
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [BDMCon] C:\Program Files\BullGuard\\bdmcon.exe
O4 - HKLM\..\Run: [BGNewsAgent] C:\Program Files\BullGuard\bgnewsag.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: OpenOffice.org 1.1.3.lnk = C:\Program Files\OpenOffice.org1.1.3\program\quickstart.exe
O4 - Global Startup: blueyonder Instant Support Tool.lnk = C:\Program Files\blueyonder IST\bin\matcli.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

Do you have any tips for not getting any new viruses? What anti-virus/firewalls do you suggest using?

Once again, your help is much appreciated smile
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16319
 
   Posted 11-14-2004 9:58 (GMT +1)    Quote: Removing backdoor trojans?Alert an admin about: Removing backdoor trojans?
Clean log, good jobsmilewinkgrin
 
Install these for safer surfing:
The nasty stuff, comes from "everywhere",  when you have installed these programs, you are well protected, update Spywareblaster once in a week, and spywareguard when you have downloaded it
 
 
Check for updates for Windows and Internet Explorer every week or so. Download each critical update one by one, rebooting when necessary.. Repeat this until you get the message "no critical updates available"

http://windowsupdate.microsoft.com/
 
You use Bullguard? It is Ok;-)
 
My pleasure:-)


Touch
Back to Top
 
New Topic Post reply to : Removing backdoor trojans? Printable version of : Removing backdoor trojans?
 
Forum Information
Currently it is Saturday, November 21, 2009 3:35 PM (GMT +1)
There are a total of 73.034 posts in 17.116 threads.
In the last 3 days there were 14 new threads and 71 reply posts. View Active Threads
Who's Online
This forum has 30334 registered members. Please welcome our newest member, sushil.
40 Guest(s), 2 Registered Member(s) are currently online.  Details
Windows, Dickens
5 Latest Threads
Constant scanning andskipped files? (3)21-11-2009 14:33:51 (Dickens)
Cannot install anti-virus softeware or do window updates... need help (17)21-11-2009 13:46:11 (superjesse)
Michael Vick jerseys (1)21-11-2009 09:42:37 (Dickens)
Arizona Cardinals Jerseys (1)21-11-2009 09:37:23 (Dickens)
How to remove this Malware/Virus (0)21-11-2009 06:54:16 (bozzack)