Author Topic: backdoor trojan  (Read 661 times)

Offline ahrim

  • Sr. Member
  • ****
  • Posts: 368
  • Karma: +0/-0
    • View Profile
backdoor trojan
« on: August 05, 2008, 12:41:47 AM »
i just got like 6 messages that popped up and said i got a backdoor trojan and every time i opened the internet everything
closed and said error report or w/e but um i turned off my comp for about 20 mins and the internet works now as you can see
although the only thing i've tried is ttg...but when i try to open mcafee it just kinda sits there on the opening screen thing..
oh right before i turned off my comp runescape opened but nothing else..if that means anything..

now i just got 3 popups from macafee saying backdoor trojan c:/files idk what it sais i closed out but it said backdoor trojan quarantined
« Last Edit: August 05, 2008, 12:49:03 AM by ahrim »
[font=\"Comic Sans MS\"][color=\"#ff0000\"]transactions:[/color][/font]

[font=\"Arial Black\"]traded a lvl 79 nezzy pure to [color=\"#ff0000\"]evil 1[/color] for 3 mems pins-[color=\"#0000ff\"]successful[/color]

traded 1 mems pin to [color=\"#ff0000\"]i w1sh i was rich[/color]
for a lvl 74 tank ranger-[color=\"#0000ff\"]successful[/color]

traded lvl 74 range tank for a lvl 91 main to[color=\"#ff0000\"] robot 99[/color]-[color=\"#0000ff\"]successful[/color]

traded a low crater bher for a lvl 93 main to [color=\"#ff0000\"]f tickle squeez[color=\"#000000\"]- [/color][/color][color=\"#00ff00\"]scammed![/color]

[/b][font=\"Comic Sans MS\"][color=\"#9932cc\"]vouch:[/color][/font][/u][/i]



evil 1

i w1sh i was rich

[font=\"Comic Sans MS\"][color=\"#000080\"][color=\"#0000ff\"]trusted:[/color]

[/i][/color][/size][/font]

robot 99

evil 1



[font=\"Comic Sans MS\"][color=\"#696969\"][color=\"#ff8c00\"]scammers:[/color]

[/color][/size][/font]

f tickle squeez[/u]





AIM=cookiedudeman





[/font][color=\"#9932cc\"]Scamming started with one person who wanted to make a profit so he started taking people for there accounts..I cant believe scammers dont feel guilt in themselves. Taking rs gp or an account away from maybe a 10 year old kid that worked night and day on his account that he loved. Scamming happened to all of us and need to stop right now. Some scammers don't even think that they might of made a 11 year old kid cry..I hope we can all stop scamming and play with trustworthiness. If you support this, put this in your sig. Thank you!!! Make thetechguide a better place![/color]

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
backdoor trojan
« Reply #1 on: August 05, 2008, 12:53:44 AM »
Download Hijackthis Installer from [color=\"#FF0000\"]HERE[/color]
For an alternate download location, you can try HERE
SAVE it to your desktop
Double click on HJTInstall.exe to run it
Choose Install

Hijackthis v2.0.2 will open

Under Main Menu, Select
Do a system scan and save a Log file
A log will open in Notepad
Copy and Paste the Whole log back here to the forum----It is all important!

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline ahrim

  • Sr. Member
  • ****
  • Posts: 368
  • Karma: +0/-0
    • View Profile
backdoor trojan
« Reply #2 on: August 05, 2008, 02:11:45 AM »
alright thankyou!
[font=\"Comic Sans MS\"][color=\"#ff0000\"]transactions:[/color][/font]

[font=\"Arial Black\"]traded a lvl 79 nezzy pure to [color=\"#ff0000\"]evil 1[/color] for 3 mems pins-[color=\"#0000ff\"]successful[/color]

traded 1 mems pin to [color=\"#ff0000\"]i w1sh i was rich[/color]
for a lvl 74 tank ranger-[color=\"#0000ff\"]successful[/color]

traded lvl 74 range tank for a lvl 91 main to[color=\"#ff0000\"] robot 99[/color]-[color=\"#0000ff\"]successful[/color]

traded a low crater bher for a lvl 93 main to [color=\"#ff0000\"]f tickle squeez[color=\"#000000\"]- [/color][/color][color=\"#00ff00\"]scammed![/color]

[/b][font=\"Comic Sans MS\"][color=\"#9932cc\"]vouch:[/color][/font][/u][/i]



evil 1

i w1sh i was rich

[font=\"Comic Sans MS\"][color=\"#000080\"][color=\"#0000ff\"]trusted:[/color]

[/i][/color][/size][/font]

robot 99

evil 1



[font=\"Comic Sans MS\"][color=\"#696969\"][color=\"#ff8c00\"]scammers:[/color]

[/color][/size][/font]

f tickle squeez[/u]





AIM=cookiedudeman





[/font][color=\"#9932cc\"]Scamming started with one person who wanted to make a profit so he started taking people for there accounts..I cant believe scammers dont feel guilt in themselves. Taking rs gp or an account away from maybe a 10 year old kid that worked night and day on his account that he loved. Scamming happened to all of us and need to stop right now. Some scammers don't even think that they might of made a 11 year old kid cry..I hope we can all stop scamming and play with trustworthiness. If you support this, put this in your sig. Thank you!!! Make thetechguide a better place![/color]

Offline ahrim

  • Sr. Member
  • ****
  • Posts: 368
  • Karma: +0/-0
    • View Profile
backdoor trojan
« Reply #3 on: August 05, 2008, 02:14:37 AM »
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:14:57 PM, on 5/11/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\LEXBCES.EXE
C:\Windows\system32\spoolsv.exe
C:\Windows\system32\LEXPPS.EXE
C:\Windows\System32\PackethSvc.exe
C:\Windows\System32\Ati2evxx.exe
C:\Windows\Cpqdiag\Cpqdfwag.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Windows\system32\inetsrv\inetinfo.exe
C:\Windows\system32\lxdccoms.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\snmp.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Windows\system32\mqsvc.exe
C:\Windows\system32\mqtgsvc.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Lexmark 1300 Series\lxdcamon.exe
C:\Windows\system32\atiptaxx.exe
C:\Windows\system32\ctfmon.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Windows\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qwest.live.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Qwest
R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\Compaq\EAB\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] c:\compaq\cpqsetup\cpqset.exe
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [SprintModemUpdate] javaw.exe -cp "C:\Program Files\Motive\FirmwareUpdater\lib\SprintModemUpdate.jar" com.motive.firmwareUpdater.client.SprintModemUpdate
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [lxdcamon] "C:\Program Files\Lexmark 1300 Series\lxdcamon.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\RunServices: [CPQDFWAG] C:\Windows\Cpqdiag\CpqDfwAg.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\Windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [MoneyAgent] "c:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O8 - Extra context menu item: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Qwest Live - {0E0A4DC9-4BDF-474D-93FF-CE6C692EFA2A} - http://qwest.live.com (file missing) (HKCU)
O9 - Extra button: Advisor - {FB602155-A965-424E-98C0-DABE71C066FF} - C:\Program Files\COMPAQ\Compaq Advisor\bin\rbaLauncher.exe (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=1c02&lc=0409
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f...p1.0.0.15-3.cab
O16 - DPF: {596AF4AC-40A0-474A-9F86-33F0A90F0FD6} (PictureItLauncher Class) - http://photos.msn.com/resources/neutral/co...ls/DigWebX2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?3471575220038
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://admin.pressplay.com/duet/registration/isetup.cab
O16 - DPF: {9903F4ED-B673-456A-A15F-ED90C7DE9EF5} (Sol Control) - http://www.worldwinner.com/games/v46/sol/sol.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE} (Microsoft Office Tools on the Web Control) - http://dgl.microsoft.com/downloads/outc.cab
O16 - DPF: {F5C90925-ABBF-4475-88F5-8622B452BA9E} (Compaq System Data Class) - http://wwemail.support.hp.com/fd2/objects/SysQuery.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\Windows\System32\Ati2evxx.exe
O23 - Service: Compaq Advisor (Compaq_RBA) - NeoPlanet - C:\Program Files\Compaq\Compaq Advisor\bin\compaq-rba.exe
O23 - Service: Compaq Remote Diagnostics Enabling Agent (CpqDfwWebAgent) - Compaq Computer Corporation - C:\Windows\Cpqdiag\Cpqdfwag.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\Windows\system32\LEXBCES.EXE
O23 - Service: lxdc_device -   - C:\Windows\system32\lxdccoms.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\Windows\System32\PackethSvc.exe

--
End of file - 9061 bytes
[font=\"Comic Sans MS\"][color=\"#ff0000\"]transactions:[/color][/font]

[font=\"Arial Black\"]traded a lvl 79 nezzy pure to [color=\"#ff0000\"]evil 1[/color] for 3 mems pins-[color=\"#0000ff\"]successful[/color]

traded 1 mems pin to [color=\"#ff0000\"]i w1sh i was rich[/color]
for a lvl 74 tank ranger-[color=\"#0000ff\"]successful[/color]

traded lvl 74 range tank for a lvl 91 main to[color=\"#ff0000\"] robot 99[/color]-[color=\"#0000ff\"]successful[/color]

traded a low crater bher for a lvl 93 main to [color=\"#ff0000\"]f tickle squeez[color=\"#000000\"]- [/color][/color][color=\"#00ff00\"]scammed![/color]

[/b][font=\"Comic Sans MS\"][color=\"#9932cc\"]vouch:[/color][/font][/u][/i]



evil 1

i w1sh i was rich

[font=\"Comic Sans MS\"][color=\"#000080\"][color=\"#0000ff\"]trusted:[/color]

[/i][/color][/size][/font]

robot 99

evil 1



[font=\"Comic Sans MS\"][color=\"#696969\"][color=\"#ff8c00\"]scammers:[/color]

[/color][/size][/font]

f tickle squeez[/u]





AIM=cookiedudeman





[/font][color=\"#9932cc\"]Scamming started with one person who wanted to make a profit so he started taking people for there accounts..I cant believe scammers dont feel guilt in themselves. Taking rs gp or an account away from maybe a 10 year old kid that worked night and day on his account that he loved. Scamming happened to all of us and need to stop right now. Some scammers don't even think that they might of made a 11 year old kid cry..I hope we can all stop scamming and play with trustworthiness. If you support this, put this in your sig. Thank you!!! Make thetechguide a better place![/color]

Offline ahrim

  • Sr. Member
  • ****
  • Posts: 368
  • Karma: +0/-0
    • View Profile
backdoor trojan
« Reply #4 on: August 05, 2008, 02:23:11 AM »
hm why does it say 9:14 pm on may 11'th it's like 2 40 am..and im pretty sure it's not may 11'th..http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/huh.gif\' class=\'bbc_emoticon\' alt=\':huh:\' />
[font=\"Comic Sans MS\"][color=\"#ff0000\"]transactions:[/color][/font]

[font=\"Arial Black\"]traded a lvl 79 nezzy pure to [color=\"#ff0000\"]evil 1[/color] for 3 mems pins-[color=\"#0000ff\"]successful[/color]

traded 1 mems pin to [color=\"#ff0000\"]i w1sh i was rich[/color]
for a lvl 74 tank ranger-[color=\"#0000ff\"]successful[/color]

traded lvl 74 range tank for a lvl 91 main to[color=\"#ff0000\"] robot 99[/color]-[color=\"#0000ff\"]successful[/color]

traded a low crater bher for a lvl 93 main to [color=\"#ff0000\"]f tickle squeez[color=\"#000000\"]- [/color][/color][color=\"#00ff00\"]scammed![/color]

[/b][font=\"Comic Sans MS\"][color=\"#9932cc\"]vouch:[/color][/font][/u][/i]



evil 1

i w1sh i was rich

[font=\"Comic Sans MS\"][color=\"#000080\"][color=\"#0000ff\"]trusted:[/color]

[/i][/color][/size][/font]

robot 99

evil 1



[font=\"Comic Sans MS\"][color=\"#696969\"][color=\"#ff8c00\"]scammers:[/color]

[/color][/size][/font]

f tickle squeez[/u]





AIM=cookiedudeman





[/font][color=\"#9932cc\"]Scamming started with one person who wanted to make a profit so he started taking people for there accounts..I cant believe scammers dont feel guilt in themselves. Taking rs gp or an account away from maybe a 10 year old kid that worked night and day on his account that he loved. Scamming happened to all of us and need to stop right now. Some scammers don't even think that they might of made a 11 year old kid cry..I hope we can all stop scamming and play with trustworthiness. If you support this, put this in your sig. Thank you!!! Make thetechguide a better place![/color]

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
backdoor trojan
« Reply #5 on: August 05, 2008, 12:43:59 PM »
Do a "System scan only" with Hijackthis and put a check next to these entries:

R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f...p1.0.0.15-3.cab


After you have ticked the above entries, close All other open windows
Including this one
Leave Hijackthis open and click FIX CHECKED
OK the prompt and exit Hijackthis

Reboot your computer

Back in Windows
Can you ensure the clock setting on your computer is set right
Including date/time/time zone
Double click on the clock on the bottom right hand of the screen
Adjust accordingly
 
Then
Download [color=\"#008000\"]Deckard's System Scanner (dss.exe)[/color] to your desktop.
Close all applications and windows.
Double-click on dss.exe to run it and follow the prompts.
When the scan is complete, two text files will open; main.txt, which will be maximized and extra.txt, which will be minimized.

Post back the Whole contents of Main.txt and Extra.txt
« Last Edit: August 05, 2008, 12:44:58 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here