This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Heap of Trouble :Win32.Backdoor.Agent & Others

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

LD,

I'm in bad shape again. Before I removed Spybot S&D I ran it then Adaware. Cleaned it. Rebooted. Spybot sent a registry change notice and asked for approval. I thought it was from the cleaning and OK'd it. Seconds later the email proliferation restarted.

Here's an adaware log, norton log and hijack log. I'm working off of my laptop again for obvious reasons.

What now?
ADWARE.BHO(GENERIC)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=Regkey : clsid\{f10587e9-0e47-4cbe-84ae-7dd20b8684bb}
obj[1]=Regkey : interface\{f7d09218-46d7-4d3d-9b7f-315204cd0836}
obj[2]=Regkey : typelib\{e63648f7-3933-440e-b4f6-a8584dd7b7eb}
obj[3]=Regkey : software\microsoft\windows\currentversion\explorer\browser helper objects\{f10587e9-0e47-4cbe-84ae-7dd20b8684bb}
obj[4]=Regkey : e404.e404mgr
obj[5]=Regkey : e404.e404mgr.1

Category: Security risks
Date Time,Feature,Risk Name,Result,Item Type,Virus Definition Version,Product Version,User Name,Computer Name,Details
1/1/2008 11:06:43 AM,Virus scanner,,Backup only,File,,10.4.0.13,SYSTEM,HAROLD,"Source: c:\WINDOWS\SYSTEM32\xpdx.sys,Action taken: Backup only"
1/1/2008 9:20:39 AM,Virus scanner,,Backup only,File,,10.4.0.13,SYSTEM,HAROLD,"Source: c:\WINDOWS\SYSTEM32\xpdx.sys,Action taken: Backup only"
1/1/2008 9:20:39 AM,Virus scanner,Backdoor.Trojan,Fully removed,File,2007.12.31.002,10.4.0.13,SYSTEM,HAROLD,"Source: [b138.exe] inside of [c:\documents and settings\hman\local settings\temporary internet files\content.ie5\mx9jhea5\8154ff2675af1b6e0677560871425153[1].zip],Risk category: Virus,Overall Risk Impact: High,Performance: 1,Privacy: 1199171985,Action taken: Fully removed"
1/1/2008 9:20:39 AM,Virus scanner,,Backup only,File,,10.4.0.13,SYSTEM,HAROLD,"Source: c:\WINDOWS\SYSTEM32\xpdx.sys,Action taken: Backup only"
1/1/2008 12:59:21 AM,Auto-Protect,Backdoor.Trojan,Blocked,File,N/A,10.4.0.13,SYSTEM,HAROLD,"Source: C:\Documents and Settings\Hman\Local Settings\Temp\AAWTMP\C523312\200119\b138.exe,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Action taken: Blocked"
1/1/2008 12:41:01 AM,Auto-Protect,Trojan.Dropper,Blocked,File,N/A,10.4.0.13,SYSTEM,HAROLD,"Source: C:\WINDOWS\SYSTEM32\0.7887232.exe,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Action taken: Blocked"
1/1/2008 12:40:58 AM,Auto-Protect,Trojan.Dropper,Blocked,File,N/A,10.4.0.13,SYSTEM,HAROLD,"Source: C:\WINDOWS\SYSTEM32\0.7887232.exe,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Action taken: Blocked"
1/1/2008 12:40:55 AM,Auto-Protect,Trojan.Dropper,Blocked,File,N/A,10.4.0.13,SYSTEM,HAROLD,"Source: C:\WINDOWS\SYSTEM32\0.7887232.exe,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Action taken: Blocked"
1/1/2008 12:40:06 AM,Auto-Protect,Downloader,Blocked,File,N/A,10.4.0.13,SYSTEM,HAROLD,"Source: C:\WINDOWS\SYSTEM32\ardCo17\ardCo172314.exe,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Action taken: Blocked"
1/1/2008 12:38:54 AM,Auto-Protect,Backdoor.Trojan,Blocked,File,N/A,10.4.0.13,SYSTEM,HAROLD,"Source: C:\WINDOWS\b138.exe,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Action taken: Blocked"
12/29/2007 12:01:31 PM,Auto-Protect,Downloader,Fully removed,File,2007.12.28.003,10.4.0.13,SYSTEM,HAROLD,"Source: C:\qoobox\Quarantine\C\WINDOWS\mrofinu1000512.exe.vir,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Privacy: 1198947678,Action taken: Fully removed"
12/29/2007 12:01:29 PM,Auto-Protect,Downloader,Fully removed,File,2007.12.28.003,10.4.0.13,SYSTEM,HAROLD,"Source: C:\qoobox\Quarantine\C\WINDOWS\mrofinu1239.exe.vir,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Privacy: 1198947676,Action taken: Fully removed"
12/29/2007 12:01:28 PM,Auto-Protect,Infostealer,Fully removed,File,2007.12.28.003,10.4.0.13,SYSTEM,HAROLD,"Source: C:\qoobox\Quarantine\C\tsqfy.exe.vir,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Privacy: 1198947672,Action taken: Fully removed"
12/29/2007 12:01:28 PM,Auto-Protect,Infostealer,Fully removed,File,2007.12.28.003,10.4.0.13,SYSTEM,HAROLD,"Source: C:\qoobox\Quarantine\C\fych.exe.vir,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Privacy: 1198947637,Action taken: Fully removed"
12/25/2007 1:52:39 PM,Virus scanner,,Backup only,File,,10.4.0.13,SYSTEM,HAROLD,"Source: c:\WINDOWS\SYSTEM32\xpdx.sys,Action taken: Backup only"
12/24/2007 5:02:40 PM,Virus scanner,,Backup only,File,,10.4.0.13,SYSTEM,HAROLD,"Source: c:\WINDOWS\SYSTEM32\xpdx.sys,Action taken: Backup only"
12/24/2007 5:02:40 PM,Virus scanner,,Backup only,File,,10.4.0.13,SYSTEM,HAROLD,"Source: c:\WINDOWS\SYSTEM32\xpdx.sys,Action taken: Backup only"
12/23/2007 9:29:08 PM,Virus scanner,,Backup only,File,,10.4.0.13,SYSTEM,HAROLD,"Source: c:\WINDOWS\SYSTEM32\xpdx.sys,Action taken: Backup only"
12/23/2007 9:29:08 PM,Virus scanner,Adware.MaxSearch,Fully removed,File,2007.12.23.002,10.4.0.13,SYSTEM,HAROLD,"Source: [b122.exe] inside of [c:\documents and settings\hman\local settings\temporary internet files\content.ie5\akyb5d73\a8f5a020e4b833865a1034489887c8b9[1].zip],Risk category: Adware,Overall Risk Impact: Medium,Performance: 0,Privacy: 1198455014,Action taken: Fully removed"
12/23/2007 9:29:08 PM,Virus scanner,Downloader,Fully removed,File,2007.12.23.002,10.4.0.13,SYSTEM,HAROLD,"Source: [vmain.class] inside of [c:\documents and settings\hman\.jpi_cache\jar\1.0\jvmusafe.jar-6ba32b3d-6c67f728.zip],Risk category: Virus,Overall Risk Impact: High,Performance: 1,Privacy: 1198454091,Action taken: Fully removed"
12/23/2007 9:29:08 PM,Virus scanner,Trojan.Gpcoder.E,Fully removed,File,2007.12.23.002,10.4.0.13,SYSTEM,HAROLD,"Source: ,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Privacy: 1198453556,Action taken: Fully removed"
12/23/2007 9:28:07 PM,Virus scanner,,Backup only,File,,10.4.0.13,SYSTEM,HAROLD,"Source: c:\WINDOWS\SYSTEM32\xpdx.sys,Action taken: Backup only"
12/23/2007 6:28:22 PM,Auto-Protect,Adware.MaxSearch,Blocked,File,N/A,10.4.0.13,SYSTEM,HAROLD,"Source: C:\WINDOWS\b122.exe,Risk category: Adware,Overall Risk Impact: Medium,Performance: 0,Privacy: 1198452502,Action taken: Blocked"
12/23/2007 6:20:51 PM,Auto-Protect,Trojan.Dropper,Blocked,File,N/A,10.4.0.13,SYSTEM,HAROLD,"Source: C:\Documents and Settings\Hman\Local Settings\Temporary Internet Files\Content.IE5\AKYB5D73\installer[1].exe,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Action taken: Blocked"
12/23/2007 6:20:51 PM,Auto-Protect,Downloader,Blocked,File,N/A,10.4.0.13,SYSTEM,HAROLD,"Source: C:\WINDOWS\SYSTEM32\ardCo17\ardCo172314.exe,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Action taken: Blocked"
11/10/2007 6:13:43 PM,Virus scanner,Adware.SystemProcess,Fully removed,File,2007.11.10.007,10.4.0.13,SYSTEM,HAROLD,"Source: ,Risk category: Adware,Overall Risk Impact: High,Performance: 0,Privacy: 1194736190,Action taken: Fully removed"

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:45:05 PM, on 1/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\SiteAdvisor\6253\SAService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SYSTEM32\notepad.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://63.138.132.82/exchange
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: MySpace Customizer Toolbar - {423a0a67-20c5-4b79-a4b7-2456e79acf5a} - C:\Program Files\MySpace_Customizer\tbMyS1.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://my.yahoo.com/p/d.html?v"); (C:\Documents and Settings\HMAN\Application Data\Mozilla\Profiles\default\5sih44uv.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_02.src"); (C:\Documents and Settings\HMAN\Application Data\Mozilla\Profiles\default\5sih44uv.slt\prefs.js)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBho.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: MySpace Customizer Toolbar - {423a0a67-20c5-4b79-a4b7-2456e79acf5a} - C:\Program Files\MySpace_Customizer\tbMyS1.dll
O3 - Toolbar: MySpace Customizer Toolbar - {423a0a67-20c5-4b79-a4b7-2456e79acf5a} - C:\Program Files\MySpace_Customizer\tbMyS1.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\UIBHO.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\PROGRAM FILES\QUICKTIME\QTTASK.EXE" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: CachePal - {5F4A4622-8370-440e-88CC-CA2256D1A08A} - C:\WINDOWS\System32\cachepal.exe
O9 - Extra 'Tools' menuitem: CachePal - {5F4A4622-8370-440e-88CC-CA2256D1A08A} - C:\WINDOWS\System32\cachepal.exe
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted IP range: http://192.168.1.1
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemyfios.verizon.net/sdcCommo…IOS/tgctlcm.cab
O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/…nSSWebAgent.CAB
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1143671063531
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6253\SAService.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

–
End of file - 8588 bytes
* Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found: [external image: Posted Image]
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
    [external image: Posted Image]
    This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.
I'm back at work so I won't be home to do this until around 6PM tonight. Does it matter if I download Dr. Web to a flash drive and put it on my PC or do I need to do the download from the PC?

I'm back at work so I won't be home to do this until around 6PM tonight. Does it matter if I download Dr. Web to a flash drive and put it on my PC or do I need to do the download from the PC?

Shouldn't matter.
I'm running Dr. Web right now. It id'd smitRem which is a removal tool that I used before. Do yo know it?

http://noahdfear.geekstogo.com/

It's in a folder on my desktop.

It then found Virtumod.240 in is68603.exe in a Temporary Internet File (maybe it reloads on startup because I used ATF earlier and haven't been online on that pc since).

It asked me about curing is68603.exe and I chose "yes to all".

It's about 25% through the scan. The express scan found nada.

Why do you think Dr. Web flagged it?

Is the scan done?
Let it clean ( cure ) whatever it finds.

If you clean out your temp files before shutting down those will be gone, but you shouldn't be getting .exe, .com, .bat files added even to your temp files unless you were downloading something. What were you doing during that time the file was downloaded to the temp files?
Are you referring to is68603.exe? I wasn't downloading anything, at least knowingly. I must have hit a page that executed a script. I'm only 73% scanned. It has also found a .reg Trojan.StartPage and 3 Downloaders.

Are you referring to is68603.exe? I wasn't downloading anything, at least knowingly. I must have hit a page that executed a script.

I'm only 73% scanned. It has also found a .reg Trojan.StartPage and 3 Downloaders.

Good. Let it do it's job :thumbup:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI