Combofix crashed and RootkiitRepealer locked - Should I be worried?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Slider5150, Feb 24, 2010.

  1. Slider5150

    Slider5150 Private E-2

    Thanks in advance for all your help and all the help in the threads on this site.

    I came in to work this morning to find that Spybot had caught DyFuCa.InternetOptimizer on my computer. Looking for info on it, I found your site.

    A bit about my computer. This computer is running XP with Symantec Anti-virus. It is attached to our Small Business Server running SBS2003. While I was able to disable the Symantec, I couldn't disable the windows firewall as this was set by group policy.

    I followed the directions in the READ ME FIRST thread. Great stuff. Computer alraeady re-boots faster. But I had a couple of problems. While running combofix, my computer did a re-boot at the generating log file point. I let the re-boot run, and once I logged back in, combofix began again at the point of the reboot only to reboot again. Upon logging in the second time, nothing from combofix.
    So next I ran rootkitrepealer. It discovered 6 files locked to the Windows API, and while displaying an action of 'intializing' it froze. I closed the window with the non-responsive program close and tried again. Found the same 6 files, and froze in the same place.

    None of the programs I ran found anything to worry about. I then updated Spybot and ran it again, and it found nothing.

    So my first question is, do I need to worry about the failures of these two programs?

    Second question is, should I re-enable Spybot's TeaTimer?

    Thanks in advance!!

    Slider5150
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What you need to do is to attach the requested logs that you could get so we can see what is happening in your system. :)
     
  3. Slider5150

    Slider5150 Private E-2

    You got it. Here are the logs I could get. I wasn't able to get logs for Combofix and RootkitRepealer, of course.

    Thanks!
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware on your system, but I am curious about this item:
    Code:
    "C:\WINDOWS\system32\"
    $`5AEA~1      Jan 11 2010              "Y???`$`??
    Can you use windows explorer to go to the system32 folder and try to find a file with that date / right click it and choose properties and tell me what info there is about it. Does it have a signature and what is the real name of it.

    You can remove a little junk:

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.
     
  5. Slider5150

    Slider5150 Private E-2

    In response to your question about the system32 file, I could only find a folder with that date. Called

    Downloaded Installations

    2 folders under that.

    {6FDA46E3-213A-4EA4-9D36-9BD192953FD5}
    under this is
    QBFC 4.0.msi Properties says this is Quickbooks Foundation Classes v 4.0. We do have Quickbooks on this computer.

    AND

    {8C86A21D-9CBD-4174-9571-5C98193BF800}
    under this is
    HMEx Assistant Version 5.msi Says it is an installation database for HMEx, which is a program we have.

    Could the file from that date be hiding somehow?
     
  6. Slider5150

    Slider5150 Private E-2

    Junk removed.

    Thanks!
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then I wouldn't worry about it. RootRepeal often crashes, though I would be curious to know what files it reported. But if you are not having any malware issues, you can go ahead and do the final cleanup:

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to tahe cleaning procedures ian step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
      a
    9. After doing the above, you should work thru the below link:


     
  8. Slider5150

    Slider5150 Private E-2

    I re-ran RootRepeal, and once I got to the point it listed the 6 files, I stopped the scan and generated the report. Here it is. I did have Gunbroker Offline Lister on the computer, but have taken it off. Don't know about the other two.

    Thoughts?

    Can't wait to get home and run this process on my home computer!

    I will run the final cleanup tomorrow am.

    Thanks!
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The log is clean. You can now do the final cleanup instructions. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds