Root kit prob., logs attached

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mr.bones, Sep 13, 2010.

  1. mr.bones

    mr.bones Private E-2

    Hi,
    I got an infection, a phoney antivirus popup called Antivirus Doctor. It popped up at startup of any browser and prevented any use of the laptop till you clicked on it or rebooted into safe mode which didn't get the popup. But even now, in safe mode the FFox settings would be changed to auto=proxy from no proxy, SAS settings were moved to prevent auto start, ethernet keeps cutting out. I even had a 0x000000044 bsod, and problems renewing ip address and had a few Gen Host Proc for win32 errors. I have to work in safe with ntwk to send this.
    Here are the logs. Please assist.
    Cheers
    mr.bones
     

    Attached Files:

  2. mr.bones

    mr.bones Private E-2

    Re: Root kit prob., logs attached, continued

    Here are more logs...
    THX again!
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have numerous system files that are corrupt. We could try to replace them, but we may not be able to find and fix all of them. Considering the other issues you are having, I would recommend that you salvage all your personal data and files and do a complete reformat and a clean install. It is up to you as to how you wish to proceed.
     
  4. mr.bones

    mr.bones Private E-2

    Hi Tim,
    What is my best approach to off-loading my 150G of data/progs to an external hdd, including the programs that are installed, that I no longer have install pkgs for, so that I can easily restore the whole lot after a Win re-install. Can it be done so that the progs will work without individual re-installs of each?:confused I have heard of disc cloners and ghost image writers. Is that what I need?
    Thanks
    mannshands
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not that easy. The safest thing for you to do is backup your personal data immediately since your PC could possibly become unbootable at any point in time. Do not back up any executable files. This includes programs that you have downloaded since any of them could be infected. Anything you may have already backed up that is an executable type file (things you downloaded to install programs....etc) are most likely infected and will cause you to be reinfected if you reuse these files.

    Once you backup, you need to format partitions and reinstall Windows and all other software especially your protection software. Then install all updates for all software. DO NOT reinstall from any executable file backups you made while this PC was infected or you will just be reinstalling the infection.
     
  6. mr.bones

    mr.bones Private E-2

    Forget last msg. Working on too many computers at the same time, sorry!
    This unit is only 2 months old. Reinstall no problem, but seems unusual for new laptop. However, several of my other friends have the same probs, thats a lot of reinstalling.
    "... in safe mode the FFox settings would be changed to auto=proxy from no proxy, SAS settings were moved to prevent auto start, ethernet keeps cutting out. I even had a 0x000000044 bsod, and problems renewing ip address and had a few Gen Host Proc for win32 errors".
    They all live in a rural community that shares a wifi hotspot from one of their homes. It is suspected the hotspot is poisoned. How, I don't know. But while working on one of their laptops at my house, connected to my ethernet 1 to 5 switch, the infection seems to have spread to me. We shared no data between computers. Is this possible? Is my switch also infected?
    Thanks for your time
    Mr.Bones
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are using a router, it very well could be. But that often gives evidence by misdirecting web searches. The best advice would be to re-set the router to factory settings.

    You should read this:
    How to Protect yourself from malware!
     
  8. mr.bones

    mr.bones Private E-2

    I dont have access to the router settings. No misdirection yet. I am on a Motorola Canopy network. I have a rooftop antenna that has a built-in router controlled by the provider. It sends a ethernet cable to my room where it feeds an OvisLink Evo-FSH5C 1 to 5 switch. A common setup here. I see no way to reset the switch. Can a switch be infected? Will the switch reinfect me after the OS reinstall? I am hourly having to un/re plug the switch to re-establish the connection or stop a cpu eating hardware interrupt. I also get an error"another pc on network has duplicate name" often at boot. Used to be I could run 5 pc at a time without probs.
    I read your link. It infers that once you get any infection (missing patch is root of all evil)the only sure cure is a fresh OS reinstall. Then what is the point of malware removal at all? And isn't it possible to be infected even with all the patches intact? I am puzzled. Besides, its almost impossible to always be currently updated. Seems like updates come out hourly!
    Not trying to be difficult, just trying to get my head around it all. Several neighbors with the same problem and setups are waiting for me to sort all this out.
    Thanks
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your infection is different from most. And without seeing logs from the other computers in this arrangement, it would be hard to say if they also need to do a reinstall. Your's however has system files that are corrupt and need to be replaced. We could use the Recovery Console to replace these files, but it would not insure that you are completely free of malware. Plus once these types of infections start, it becomes easy for them to latch onto to other exe files. And since you are all sharing a common hub, it ups the chances that any one computer could spread the infection to the other computers. You all need to have a good firewall installed and a more secure network.

     
  10. mr.bones

    mr.bones Private E-2

    Tim- Thanks for the help. I am just gonna reinstall and quit using that LAN.
    I appreciate your time spent, especially since I checked into Forum Helper training.
    Regards
    mr.bones
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. And good luck!! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds