Rootkit.bagle

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Bagled, Jun 3, 2009.

  1. Bagled

    Bagled Private E-2

    Hi, I got infected with the rootkit.bagle about two days ago.

    Antivirus gets terminated. win32 error when I try to manually restart it.
    Wireless connection disable. Ethernet connection works though
    Blue screen warning when booting safe mode
    Random number .exe files occasionally appears in task manager. Process manager shows that they originate in Username\Application data\drivers but they are not visible.
    autochk.exe missing message during restart. This happened from yesterday, so may be caused by my (amateurish) attempts to fix things.

    I managed to manually delete a couple of the folders with the infected files(although they just reappear) but I can't empty them from the recycle bin now. Gets a "directory is not empty" message

    CCleaner which was already installed on my comp won't run. SAS and combofix both gives win32 errors, even when renamed.

    When I tried to run GMER, I get error msg "cannot create a stable subkey under a volatile parent key", but it seems to work.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. Bagled

    Bagled Private E-2

    file attached
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's the first part! Now complete the second part. ;) Then attach a new log from MGtools after running it again. And then tell me how things are working.
     
  5. Bagled

    Bagled Private E-2

    File attached. Scan took 45 mins! Doing the mgtools scan now, but I've already got back my wireless connection and CPU usage is not jumping to 100% all the time now. Still have the autochk error on startup. Another thing that happened the past day, during startup, at the black screen with windows icon and blue progress bar, the screen area is shrunken to a small area in the center. But it goes back to normal at the blue "starting windows" screen.

    Mgtools scan done, but I got a processdll.exe error (application failed to initialize properly) just before it finished. This error also happened the previous time though.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The infection has damage some of the programs you have installed so they will need to be uninstalled and reinstalled.

    First start by deleting the below from your Desktop:
    C:\Documents and Settings\Joyce\Desktop\Cix.exe
    C:\Documents and Settings\Joyce\Desktop\SAS.exe

    Now uninstall FireFox, Unlocker, and also uninstall Spybot Search & Destroy.

    Also uninstall the below old version of Sun Java:
    Java(TM) 6 Update 11

    Then immediately reboot.

    After reboot download and reinstall FireFox, Unlocker and Spybot from the below links. Make sure that you so no to using Spybot's Teatimer.

    Mozilla FireFox

    Unlocker

    SpyBot-Search & Destroy


    Now I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.

    Now run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F3 - REG:win.ini: load=
    F3 - REG:win.ini: run=
    O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKUS\S-1-5-18\..\Run: [WindowsRegKey%update] ethernet32m.exe (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [Microsoft Update Emulator] ethernet32A.exe (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [Windows Service Auto Updater] svxhost.exe (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [Windows Service Auto Updater] svxhost.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [WindowsRegKey%update] ethernet32m.exe (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunOnce: [Windows Service Auto Updater] svxhost.exe (User 'Default user')
    O23 - Service: Windows Security (WinMgt) - Unknown owner - C:\WINDOWS\system32\microsoft\protect\s-1-5-09\winmgt.exe (file missing)

    After clicking Fix, exit HJT.

    Now try to run SUPERAntiSpyware, Malwarebytes and ComboFix as requested in the READ & RUN ME.

    Now reinstall your antivirus, realtime antispyware protection, and firewall programs. If you did not have one, pick of each from the below link and install them now before you get reinfected.

    How to Protect yourself from malware!


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • the SUPERAntiSpyware log
    • the Malwarebytes log
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. Bagled

    Bagled Private E-2

    I don't know which details are important, so I'm going to list out everything I did.

    Already deleted Cix and SAS and uninstalled spybot before this.
    Moved the majority of files from desktop
    Firefox uninstall file not working, so I reinstalled the new version and then uninstalled. Also uninstalled unlocker.
    Restarted, installed firefox, realised I forgot to uninstall sun java, uninstalled firefox and sun java. Restarted
    SAS turned up Trojan.Hugipon and Trojan.SCVHost/Fake. It didn't disable internet access but the taskbar icon disappeared so I ran the network connection repair.
    MBAM turned up some Adware.BHO.
    Combofix added an IE shortcut to my desktop and reset my start menu customization.
    MGTools wouldn't run. The window would open for a split second and then close again.
    Uninstalled ProcessGuard, MBAM and Spyware blaster. Restarted.
    Tried to install Comodo Internet Security, but it became non-responsive during the online update and I terminated it with task manager. I presumed I just needed to run the update manually, but after restart, I got a limited connectivity problem and Comodo did not start. Wouldn't start manually either. The menu and tabs in task manager disappeared. Uninstalled and restarted and now the connection worked again. Menu and tabs still not there but discovered that it was double clicking at the border that toggled it.
    Ran MGTools successfully

    I'm going to try another anti-virus and firewall now.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I did not ask you to run MGtools here. I asked you to run analyse.exe which is in the C:\MGtools folder.

    I still see Comodo Internet Security/ firewall in your logs.


    I also still see the below:

    O23 - Service: Windows Security (WinMgt) - Unknown owner - C:\WINDOWS\system32\microsoft\protect\s-1-5-09\winmgt.exe (file missing)

    Did you try to fix this as requested with analyse.exe?

    I also see signs of both Threatfire and Sanboxie in your logs. Do you have both of these installed? Did you uninstall Threatfire?

    Do you know what the below are from and is it still installed?
    R3 maximir;maximir;c:\windows\system32\DRIVERS\maximir.sys [x]
    R3 maxivista;Maxi_Vista_DriverA;c:\windows\system32\DRIVERS\maxivista.sys [x]
     
  9. Bagled

    Bagled Private E-2

    Yes, I ran HJT and fixed those issues before doing the three scans. Either it reappeared, or I missed one. Should I try to fix it again?

    CIS was uninstalled, there is only two .cfg files left in the program files folder for Comodo. HJT still shows 2 entries for Comodo though.

    I have Sandboxie, installed before the infection. Threatfire was installed and uninstalled a long time ago.

    The maxivista files may be from this program that I tried, but it was also uninstalled a long time ago
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And it did not uninstall completely.

    Also did not uninstall completely.

    Try the below to finish cleaning up after these programs that did not properly uninstall and to remove the service we tried to remove. You could be having issues uninstalling things due to not properly using Sandboxie.



    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  11. Bagled

    Bagled Private E-2

    Files attached.

    Everything seems fine. I had a problem with the outpost firewall not activating properly during startup.(greyed out task bar icon. had to manually exit and restart) But the last Combofix run seems to fix that.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  13. Bagled

    Bagled Private E-2

    Yay. Thank you so much for your help, it's much appreciated.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds