Rootkit infection?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by BizR32, Jan 17, 2007.

  1. BizR32

    BizR32 Private E-2

    Thank you in advance - not only for hopefully helping me with this mess, but also for running such a great site!
    Computer started slowing down, then would occaisionally freeze. (Running XP Pro/sp2). Had been infected before, so read through forum & ran Read & Run Me First.
    Ran Spybot S&D & CounterSpy in safe mode - scans came back clean.
    Could only run BitDefender in normal mode - came back clean.
    Panda Active scan found "Zango" - will attach log.
    Also ran Kaspersky - not quite sure what it found, but will attach log.
    Got brave, ran AVG Anti-Rootkit - found "c:\windows\system32\kdkle.exe" (couldn't get it to save report).
    Bravery was short-lived. . . when the warning came up about being an "advanced user", I cried 'uncle'.
    Will also attach GetRun, ShowNew & HJT logs.
    BTW - prior to this, had tried using ZoneAlarm, but kept having problems getting it to run.
    Thanks again!
     

    Attached Files:

  2. BizR32

    BizR32 Private E-2

    Rest of logs

    Here are the remaining logs
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Rest of logs

    Please run this WareOut Removal and attach the request log.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O17 - HKLM\System\CCS\Services\Tcpip\..\{706524C5-DF95-4EDB-A251-04EA7EC3CB3A}: NameServer = 85.255.113.106,85.255.112.167
    O17 - HKLM\System\CCS\Services\Tcpip\..\{8FBA1E01-8F03-4A72-B605-8B2D4BF36788}: NameServer = 85.255.113.106,85.255.112.167
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.106 85.255.112.167
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.106 85.255.112.167

    After clicking Fix, exit HJT.

    Now reboot in normal mode
    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Also run AVG Anti-rootkit now and see if it still finds any problems.

    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  4. BizR32

    BizR32 Private E-2

    Not sure what happened:
    Downloaded WareOut Removal from second link
    Copied bold text, saved it, but did not double-click it
    Booted into safe mode & started install of WareOut Pressed "any key", something ran, then the box disappeared. No requests to reboot.
    Could not find any kind of report from it anywhere.
    Ran HJT while still in safe mode, didn't change anything, will attach log.

    Thought I better stop here until I checked with you.
    Thanks again
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't need any logs until all steps have been run. Try WareOut fix again but first shutdown the CounterSpy program! If it does not seem to work properly, complete all the steps requested anyway and attach all logs.
     
    Last edited: Jan 19, 2007
  6. BizR32

    BizR32 Private E-2

    Tried to run WareOut again, same thing happened as in previous post. Thought maybe I hadn't completely shut down CounterSpy, checked that & tried again without success.
    Continued with rest of steps. Will attach log files.
    Ran AVG Anti-Rootkit, still found "c:\windows\system32\kdkle.exe". Now for the stupid question: Should I have opted to have it 'fix it'? I didn't 'cas you didn't say to. (Just reread that - sounds a little sarcastic . . . Hope you don't take it that way! I truly appreciate the time & effort you spend helping me & others. So I print out your responses & check them off as I go, often double-checking, trying my best not to waste your time & expertise.)
    Computer still seems a little slow, but have tried not to use it too much until it gets clean.
    Thank you!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes this is part ot the WareOut infection and normally there are multiple files involved. That is why I wanted use FixWareOut first. Run AVG Anti-Rootkit and see if it can fix this file. Then reboot. And run a new scan to make sure it is fixed.

    Uninstall the CounterSpy trial now before continuing. We are finished with it.

    Then delete the below folders:
    C:\Documents and Settings\Chris\Local Settings\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Also delete the below file:
    C:\WINDOWS\unins001.exe

    Attach a new log from HJT afterwards.

    Also tell me if you are still having problems.
     
  8. BizR32

    BizR32 Private E-2

    Just keeps on giving . . .
    Ran AVG ANTI-Rootkit twice, & 'c:\windows\system32\kdkle.exe' just won't go away!
    Ran the rest of the steps without a problem. HJT log attached.
    Is there a light at the end of the tunnel, or is it a freight train?????
    Computer is running better, no longer freezing.
    Thank you again!
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try using AVG Anti-rootkit in safe boot mode. If it does not work or still does not remove the file, try using the below tool and procedure. Make sure you attach the log!!

    Using Sophos Anti-Rootkit
     
  10. BizR32

    BizR32 Private E-2

    AVG Anti-RootKit would not run in safe mode. Ran Sophos Anti-Rootkit & it found the same thing as AVG. Did not run fix. Log attached.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay see if it can fix it! If it says it is fixed, reboot and check again. Let me know the results.
     
  12. BizR32

    BizR32 Private E-2

    Chaslang - you can walk on water! And I don't mean a frozen pond in Maine! Ran Sophos, fixed the file, rebooted, ran scan again & came up clean.
    Just to be sure (& for my curiosity) ran the AVG Anti-Rootkit scan. It also came up clean. Did it not work 'cas it's a Beta version? Any thoughts on letting AVG know that it didn't work?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Like all malware type programs.... they each can do things that others cannot. Sometimes it is just a matter of catching up in a next version. Other times they just never catch up! I have also had AVG Anti-rootkit fix something that Sophos did not.

    I would like to know if you can now actually get the FixWareOut procedure to run. It would be interesting to know if the above was blocking it. If you can, attach the log.

    Also attach new logs from ShowNew and HJT!
     
  14. BizR32

    BizR32 Private E-2

    FixWareOut ran without a problem. Requested logs attached.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmmm! The log from FixWareOut indicates it was from
    Last edited 1/14/2006

    Is your date set incorrectly? If not, then the log would indicate that you did not just run FixWarOut today or that no log was produced today. That log may have been from 6 days ago.

    Your logs are clean! If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  16. BizR32

    BizR32 Private E-2

    And the mystery deepens . . . especially since my first request for help was on 1/17/07! Computer date & time is set correctly. Checked the other logs & they seem to be dated correctly.
    Will begin clean-up process.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay, my mistake! It looks like FixWareOut is showing the date the program itself was updated rather than showing a version number. It does not show the date the fix was run. So all is good! ;)
     
  18. BizR32

    BizR32 Private E-2

    Just an FYI: Decided to try Outpost Firewall. Installed OK, but none of the help screens would open. Uninstalled it, will try Zone Alarm again.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not sure what the problem with Outpost was. Did you reboot after installing and before trying to get help?
     
  20. BizR32

    BizR32 Private E-2

    Not positive, but pretty sure I had to reboot after install. Have installed Zone Alarm & so far running OK.
    Thank you again from the bottom of my hard drive! Computer is running great! And,yes! I want through your protection guide & have this puppy more secure.
    Thank you so much!
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds