No mouse or internet after rootkit (zero.access?)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by shaman420, Dec 18, 2011.

  1. shaman420

    shaman420 Private E-2

    Hello, I have a WinXP SP3 machine that was (is?) infected with a rootkit.
    The mouse does not work and the internet connection doesnt either.. (wired or wireless)

    I have:
    disabled system restore
    ran combofix, otl, avenger, rootkitrevealer, hijackthis, lspfix. winsockfix, mbam
    I have also reset the stack using netsh and reset the hosts file as well.

    When I ran combofix, it detected a rootkit (unfortunately I didnt catch the name, but it all the signs seem to point to Zero.Access) Combofix mentioned that the internet may not work ((rootkit is embedded in tcpip stack)), but to reboot, then run combofix again)

    I did this, but there has been no change.
    Malwarebytes detected a trojan and it was removed.

    I have attached the logs from the other programs.

    Currently, there is still NO MOUSE (usb or ps2) or internet connection.
    (I have a wired and wireless adapter, neither of which work.)
    Although I do have keyboard (usb) and a thumbdrive works too.

    I have never seen this before, its really tough with no mouse.
    When I 1st plug the usb mouse in, it works for a second, then stops..
    I tried running rootkit unhooker, but I can use it without a mouse.

    PLEASE HELP!!
    Aaron
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!


    Will use ComboFix to add back in a missing IPsec registry key.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. thisisu

    thisisu Malware Consultant

    Code:
    i8042prt             FALSE    OK 
    For the mouse, attempt to type the following command from command prompt (Start -> run -> cmd) and let us know what appears:
    • net start i8042prt
     
  4. shaman420

    shaman420 Private E-2

    Thank you for your replies.

    Two things, first, how can I drag something without a mouse?

    Second, here is the error I get when running net start i8042prt

    system error 1058 has occurred

    the service cannot be started either because it is disabled or it has no enabled devices associated with it.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on additional checks of your logs, you have other services stopped that need to be running too. Had anyone been experimenting with disabling services to improve performance. Just doing a quick look, besides the i8042prt service I also see the below:
    Code:
    SSDPSRV                         FALSE    OK 
    upnphost                        FALSE    OK 
    see if you can use the below to start these:

    net start ssdpsrv
    net start upnphost

    Then see if the i8042prt will start.

    Have you tried using other user accounts on this PC. If not, try others and see if the mouse works.

    I also noticed in your first message you said you disabled System Restore. This was bad idea. We never disable system restore until we are finished removing malware. You now have no ability to attempt using system restore to fix registry entries that may have been changed. Also you have no fallbacks if something goes wrong during malware removal. So at least turn system restore back on now so that you at least have the current state saved.


    Since you seem to be able to navigate around using your keyboard to perform various tasks, see if you can get the below file save to this PC. If you can then from Windows Explorer, navigate to the file using your keyboard and once you have the file selected, hit enter

    fixserv.reg

    And allow it to be added to the registry. If you can accomplish this, then reboot and see where things stand.
     
  6. shaman420

    shaman420 Private E-2

    OK, I was able finally drag the txt file over combofix.
    I also ran getlogs.bat - the logs are attached..

    Not sure about the other services, I did not stop any specifically.

    I tried to run those 2 commands, I got these errors..

    net start ssdpsrv -
    SSDP Discovery service could not be started.
    The service did not report an error.

    net start upnphost -
    System error 1068 has occurred
    The dependency service or group failed to start

    net start i8042prt -
    same error as before

    I then ran the .reg file and rebooted.
    BOTH WIRED AND WIRELESS ARE BACK!!

    I disabled system restore due to the idea that the malware can get backed up too, this way the restore files get purged., when I rebooted after running the .reg file, system restore was back on..

    So now I have internet.. I still have NO MOUSE..

    The logs are attached are from before the .reg file..

    THANK YOU!
    Now to get a mouse back...

    You guys are wizards.
     

    Attached Files:

  7. shaman420

    shaman420 Private E-2

    Update:

    OK, I ran net start ssdpsrv again and got a new error

    system error 2 has occurred
    the system cannot find the file specified.

    net start upnphost throws the same error.

    I booted into safe mode to get into the administrator account but still have no mouse.

    Should I run some of these tools again and re-post the logs?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but this is the wrong approach to take as shown in our cleaning procedures. Contrary to what AV companies tell you to do. You should not do this until you have remove all malware and gotten your PC working properly. Those restore points even if infected are better than none at all especially if/when something goes wrong. In fact one of them, may have been able to fix your problems. Any infections reinstalled can always be removed again especially when you use a forum like ours to help you.

    Okay so we have made a little progress getting your wired and wireless interfaces working which is good.
    I'm a little surprise at this though since your logs still show that IPsec, DHCP and other services are not running.

    If your mouse is working once in awhile, it is not sounding like a malware problem but rather a Windows problem. If services or drivers required for the mouse were broken or missing, it would be unlikely that it would work sometimes and not others. Are you sure you are not having a hardware problem with this mouse?

    See if you can bring up MSconfig and select Normal Startup as requested in step 4 of the READ & RUN ME FIRST. Then OK and then reboot your PC so that all the processes and services you disabled with MSconfig load properly.

    Then run C:\MGtools\GetLogs.bat by selecting it and hitting enter on your keyboard.

    Attach the new MGlogs.zip file.
     
  9. shaman420

    shaman420 Private E-2

    The logs in my last post were made BEFORE I ran the .reg file you provided.

    As far as the mouse issue, I have used multiple USB mice.
    When I reboot, I can plug one in, and as Windows finds and installs drivers, I get about 3 seconds of a mouse, then, it stops. I ONLY get mouse for those few seconds after plugging in the mouse.
    I was lucky enough to drag the CFscript over combofix during those 3 seconds.

    I have used multiple mice in multiple usb ports, they all do the same thing, I dont think its a hardware issue with the mouse itself.
    The PS2 mouse has not worked at all since the infection.

    I also updated the chipset drivers during this as well. This board has both usb2 and usb3 ports. (in case the drivers were corrupted)

    I have set the startup to normal and ran the batch file.
    The logs are attached.

    Thank you again for your time and assistance.
    I really appreciate it.
     

    Attached Files:

  10. shaman420

    shaman420 Private E-2

    For the sake of more info, I also checked the BIOS and verified that usb and legacy devices were enabled.
    (I did this way before I posted in the 1st place.)

    For the record, you rock.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ah! That explains it.

    Well what we have accomplished is the below. You can see which service/drivers are still not running and which we have fixed since starting.
    Code:
    Service states
    ================================
    ALG                  FALSE    OK        Fixed
    Dhcp                 FALSE    OK        Fixed
    Dnscache             FALSE    OK        Fixed
    Nla                  FALSE    OK        Fixed
    NVSvc                FALSE    OK        Fixed
    PolicyAgent          FALSE    OK        Fixed
    SharedAccess         FALSE    OK        Fixed
    SSDPSRV              FALSE    OK        [B][COLOR=darkred]Still not correct[/COLOR][/B]
    upnphost             FALSE    OK        [B][COLOR=darkred]Still not correct [/COLOR][/B]
    WebClient            TRUE    Degraded   Fixed
     
    Service Driver states
    ================================
    i8042prt             FALSE    OK        [B][COLOR=darkred]Still not correct   [/COLOR][/B]
    IpFilterDriver       FALSE    OK        [B][COLOR=darkred]Still not correct  [/COLOR][/B]
    IpNat                FALSE    OK        Fixed      
    IPSec                FALSE    OK        Fixed  
    Tcpip                FALSE    OK        Fixed   
    The main ones inhibiting your mouse are i8042prt, SSDPSRV. The upnphost is dependent on SSDPSRV so it may start as soon as SSDPSRV is started.


    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1

    Download Mirror #2
    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      i8042prt.sys
      
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. You can just close this notepad window since the log is already saved on your Desktop. Be patient! It may look like it is not doing anything, but it takes awhile for this to scan thru your whole system look for matches.
    • Please attach the SystemLook.txt log found on your Desktop to next reply.
     
    Last edited: Dec 20, 2011
  12. shaman420

    shaman420 Private E-2

    Here is that logfile...
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run the search again and this time search for the filename I requested. Your search results showed that you searched for i8042 but I asked you to search for i8042prt.sys
     
  14. shaman420

    shaman420 Private E-2

    My apologies, I hadnt had coffee yet...

    Oddly enough, as I mentioned, I could remove the usb mouse for a while, then plug it in and get mouse very briefly, when I did it this last time, one of the mice is actually working!!! More than a few seconds!!

    The ps2 is not working still, nor is another usb.
    One mouse is actually working, Im almost afraid to reboot in fear of losing the mouse..

    I have attached the correct logfile..
     

    Attached Files:

  15. shaman420

    shaman420 Private E-2

    So I rebooted. and removed all usb devices and ps2 mouse..
    When off, I inserted ps2 mouse..

    Upon reboot, no mouse again, I plugged in a usb mouse and the same 3 second behavior started again..
     
  16. shaman420

    shaman420 Private E-2

    All the mice I have work when booting to UBCD4WIN, so I know its not a hardware problem...

    No mouse again....
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download and save the below to the C:\MGtools folder. Then select it and run it. It will run in less than 10 seconds.

    GetMsrv.bat

    Once it finishes, it will update the C:\MGlogs.zip file. Attach the updated log.
     
  18. shaman420

    shaman420 Private E-2

    Here you go, thank you yet again..
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Then reboot your PC.

    Then rerun the GetMsrv.bat file I had you download.

    Once it finishes, it will update the C:\MGlogs.zip file. Attach the updated log.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I just found that the below is missing from your registry too


    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SSDPSRV\0000\Control]
    "ActiveService"="SSDPSRV"


    But this will take some additional work to get permissions to import this. And I have to leave for work now.
     
  21. shaman420

    shaman420 Private E-2

    Well, I broke down a installed Win7..

    I really appreciate your help on this matter, but I felt it was time.

    Good news is everything runs better than ever before!

    Thank you so much again for your time..
    Aaron
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Sorry we could not help you get this fixed. This is new type problem that has just recently started occurring, and right now, there is no easy fix for them. In fact, there may be no fix other than reinstall as their could be too much damage to the registry and files to repair. This would just render the PC very unreliable.

    It seems the hacker's goal is to now destroy a user's PC when any attempt is made to remove the malware.
     
  23. shaman420

    shaman420 Private E-2

    I feel that we would have gotten it, but as you mentioned, would it be worth it. The PC may never run good with that installation.

    Ill be back, this forum is great..
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that is one of my big concerns right now with these new infections. Even if we get the problems on the service resolved, there may be many instabilities due to other uncovered problems/damage that we could not see.
     
  25. shaman420

    shaman420 Private E-2

    Guess what.

    It looks like it can travel the network..
    I have it on another computer, same infection.

    I have mouse though. Is the fixserv.reg file you posted safe to run on a different PC, this one is also running XP (media center)?
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It doesn't surprise me.

    Yes it should be okay on this PC but that may not be enough to fix your networking problems. We also had to fix IPsec first last time. You really would be better served starting a new thread for this second computer so that we can properly see what is going on. Applying registry patches without first removing any hiding malware, may be a waste of time.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds