Help Resolve Rootkit infection

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mesaboog, Jan 4, 2008.

  1. mesaboog

    mesaboog Private E-2

    I recently have been infected with some type of virus and/or malware. I have tried to run SpyBotSD, but when I install, the virus automatically deletes the SpyBotSD.exe. So, I renamed and copied the SpyBotSD.exe from an unaffected machine and copied it into the SpyBot directory of infected machine and managed to run SpyBot in SAFE mode. This found some cookies, but didn't resolve many of my issues. Apparently, whatever virus I have, makes it impossible for me to install AV software. When I got infected, it compromised Norton. So, I uninstalled and used Norton's unistall utility to remove all traces. I then tried to install AVG, but the install fails. I then tried Avast! and it installed and scanned at reboot (found a virus and a malware), but again, when Windows loaded, the .exe file for Avast! is gone. I was able to run Adaware with no problems and fixed all problems found there. I have run HijackThis and Kaspersky and am submitting the logs below. Any assistance you can provide is greatly appreciated. I can alos provide a log from the Avast! boot scan upon request.


    Edit by chaslang: Inline HJT log removed. READ & RUN ME sticky not followed.
     
    Last edited by a moderator: Jan 4, 2008
  2. mesaboog

    mesaboog Private E-2

    And here is the Kaspersky log

    Let me know if you need anything else. I sincerely appreciate the help.

    -------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER REPORT
    Friday, January 04, 2008 7:22:42 AM
    Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
    Kaspersky Online Scanner version: 5.0.98.0
    Kaspersky Anti-Virus database last update: 3/01/2008
    Kaspersky Anti-Virus database records: 502274
    -------------------------------------------------------------------------------

    Edit by chaslang: Inline Kaspersky log removed. READ & RUN ME sticky not followed.
     
    Last edited by a moderator: Jan 4, 2008
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  4. mesaboog

    mesaboog Private E-2

    Well, I am striking out here.

    Read and Run progress:

    Remove Antivirus Apps: Cannot uninstall completely Avast!. It never completely installed and I was unable to run it initially. This probably explains why I cannot uninstall correctly.

    Firewall: I am only running Windows Firewall

    1 House Cleaning:
    Uninstall Malware Progs - Done
    MSCONFIG set to Normal - Done
    All Quarantine Folders Deleted - Done
    Empty Recycle Bin - Done
    Empty Norton Nprotect - N/A
    Download and Install CCleaner - Will install, but nothing happens when I try to run it. Tried to run in SAFE mode, but I can't run in Safe mode...just keeps rebooting.

    2 Enable viewing of hidden and System files - Done

    3 XP Cleaning:
    ComboFix.exe - Downloaded, but when I run it, I get the following error: c:\progra~1\\Symantec\s32evnt1.dll. An installable Virtual Device Driver failed DLL initialization.
    choose 'close' to terminate the application.
    SpyBot - Search and Destroy - Can't run because .exe disappears on install.
    AVG Anti-Spyware - Can't install - Get following error: The installer you are trying to use is corrupted or incomplete. This could be the result of a damaged disk a failed download or a virus.
    MGtools: I have not tried this yet due to my failure with the everything else so far.

    I think I need more assistance since I cannot run the progs to provide the scan logs you need.

    Thanks in advance for your assistance!
     
  5. mesaboog

    mesaboog Private E-2

    Well, I was able to correct the error: c:\progra~1\\Symantec\s32evnt1.dll. An installable Virtual Device Driver failed DLL initialization by editing the VDD reg key. Subsequently, I have been able to run MGlogs and ComboFix. I added the combofix.txt log into the MGlogs.zip archive.

    Please have a look and let me know what my next steps ought to be.

    Thanks so much for the assistance!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to download ComboFix from our link and then rerun it. It appears that you are using a very outdated version or there is still some kind of error.

    Also the scans that are part of MGtools did not work properly. Did you fix the error: c:\progra~1\\Symantec\s32evnt1.dll. Before or after running MGtools. You don't need to rerun the MGtools.exe anymore once it is installed the first time. You can just run the C:\MGtools\GetLogs.bat file to run all the scans. You need to run this and again watch for error messages like those mentioned on the Using MGtools download page.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also you said you could not install Spybot, but I see Spybot's Teatimer in your HijjackThis log.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm going to give you starting cleaning steps to see if we can make things a little better. They may or may not work properly since we do not have all of the required info from logs yet. Let's try anyway.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [Free Radio] C:\Program Files\Free Radio\radio.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [mule_st_key] C:\Documents and Settings\User\Application Data\m\flec006.exe
    O4 - HKCU\..\Run: [drvsyskit] C:\WINDOWS\system32\drivers\hldrrr.exe
    O4 - HKCU\..\Run: [german.exe] C:\WINDOWS\system32\wintems.exe
    O20 - Winlogon Notify: msldr32 - msldr32.dll (file missing)

    After clicking Fix, exit HJT.

    If you cannot boot in safe mode to do the below steps, just reboot your PC back into normal mode and then try to do the below steps in normal boot mode.

    Now reboot into safe mode and delete the below files. Keep track of what you find and don't find and what gets deleted. Report back later.
    C:\Program Files\Free Radio\radio.exe
    C:\Documents and Settings\User\Application Data\m\flec006.exe
    C:\WINDOWS\system32\drivers\hldrrr.exe
    C:\WINDOWS\system32\wintems.exe
    C:\WINDOWS\system32\msldr32.dll

    Now while in safe mode, delete the below folders
    C:\Program Files\Free Radio
    C:\Documents and Settings\User\Application Data\m

    Now reboot in normal mode

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created.

    Make sure you tell me how things are working now!
     
  9. mesaboog

    mesaboog Private E-2

    Hi chaslang,

    Thanks so much for your assistance. Before your last post, I ran the correct ComboFix.exe and the new logs. They are attached. Please advise next steps.

    Cheers,

    Scott
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you do my last steps yet? If does not look like it. Give them a run.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The scans from MGtools are still not running properly. You need to telll me if you are seeing any error messages.
     
  12. mesaboog

    mesaboog Private E-2

    Thanks chaslang,

    I ran MGT again and just after "updating runkeys.txt", I get many lines of the same error: "The process cannot access the file because it is being used by another process".

    Does that help?
     
  13. mesaboog

    mesaboog Private E-2

    Hi chaslang,

    Well after spending quite a bit of time last night, I think I am in the home stretch. I was able to run all of the utilities and here are the updated logs. Please have a look and see if things look clean.

    Thanks,

    Scott
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean. You never answered my questions about the list of things I gave you to delete so I assume you found and removed all of them with no problems.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    12. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds