Aggressive Rootkit seems Unremovable

Discussion in 'Malware Help (A Specialist Will Reply)' started by alexp91, Jan 6, 2008.

  1. alexp91

    alexp91 Private E-2

    So far, I've run Lavasoft Ad-Aware, Spybot, Windows Defender, AVG Anti-Virus, and Norton Anti-Virus for viruses that are not hidden. None of these, accordingly, found the rootkit that I know I have (besides this rootkit, my computer is apparently very clean).

    On top of this, AVG Anti-Virus (Free Version), Windows Defender, and Norton should be protecting my computer (using real-time Resident Protection) from this stuff (I don't really trust Norton anymore because it never finds ANYTHING), but they don't. In addition, ProcessGuard pretends it's protecting my from malware when I "permit" my own programs, but never finds anything else.

    Then I ran AVG Anti-Rootkit (which seems the most successful anti-virus tool, right before SpyBot, from personal statistics) and found something in my C:\WINDOWS\System32\Drivers\ folder that I deleted. It prompts me to restart my computer, which I did. Then, after I sign back on and run AVG Anti-Rootkit once again, I find another rootkit in the same folder under a slightly altered name. I delete it, restart, and the process repeats itself.

    Is there any sure-fire way to remove this piece of malware? I installed Sophos Anti-Rootkit, but it didn't even find a rootkit, unlike AVG.

    If possible, could someone please tell me whether my defense (which seems like more than enough to me) is deficient, and how to remove this one rootkit that seems to survive multiple deletions?

    Thanks a lot
    -Alex
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. alexp91

    alexp91 Private E-2

    The Anti-Spyware is taking a few hours to complete, so I'll post that later.

    The reason I know I have this problem is because my computer usage is normally around 1-5%, but recently it's been 50% and above (sometimes even sitting at 100% for minutes).

    I included the MGtools and ComboFix analysis in the attachments, and a partial screenshot of all the maintenance tools I have run to explore this problem (only of which AVG Anti-Rootkit has found a reccurring one).
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to let the MGTools.bat run until completion ....don't close down the window until it has finished running all 5 logs.
     
  5. alexp91

    alexp91 Private E-2

    Oh sorry. I tried clicking the Superman icon, and it just sat at that MSConfig screen for five minutes. Now I tried clicking the analyes.exe, and I scanned. It says it completed, and I saw a .txt file, but it disappeared and I didn't exit out of it. Just to confirm, I'll load a screenshot of the program that I think I should be running (analyes.exe).

    I think, possibly, since I saw the .txt file, it overwrote the new log over the previous MGtools.zip. I tried to upload the newer one, but it says there is already an MGtools.zip in the thread, and I can't upload this one.

    Maybe it'd be better if I could find the text file and copy and paste it here?

    Thanks.
     

    Attached Files:

  6. alexp91

    alexp91 Private E-2

    I think one of these may be the one you requested, actually.

    The top part of the .zip file is removed (only the unnecessary stuff) because I tried to cut it down 7 kb, but was unable to so I just zipped it.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip
     
  8. alexp91

    alexp91 Private E-2

    Ok done.
    Will you still be needing the Anti-Spyware log report after its finished (probably another half hour to hour)?
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That and the ComboFix log .....but I need to go for a while so I will look at the logs and get back to you. :)
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok...I took a quick look and the things you need to do are as follows:
    Uninstall:
    J2SE Runtime Environment 5.0 Update 8"
    J2SE Runtime Environment 5.0 Update 9"
    Java 2 Runtime Environment, SE v1.4.2_03
    LimeWire PRO 4.12.6
    Viewpoint Manager (Remove Only)"
    Viewpoint Media Player

    You have multiple anti-virus programs running ...you need to uninstall all but one:
    PC Tools AntiVirus3.6
    Norton 360
    AVG 7.5

    Now tell me exactly what the system32\drivers file is that you say keeps coming back or is reported by which ever program is reporting it.
     
  11. alexp91

    alexp91 Private E-2


    I've uninstalled all of the non-antivirus programs so far (good bye free music), but I'm on the antivirus programs now. Do you suggest a specific one? Right now, I'm leaning on sticking with PC Tools AntiVirus3.6, and ditching the other two, even though they have a more famous name.

    Although the screenshot shows the file name, evertime I delete and it reboot (as prompted to do so), it comes back with a similar, yet different name. So this is just one variant in the screenshot.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Norton is a known resource hog ..so I would uninstall that and AVG if you prefer the other.

    Please download GMER and save it to your desktop:
    • Unzip (extract) it to your desktop.
    • Disconnect from Internet and close all running programs.
    • There is a small chance this application may crash your computer so save any work you have open.
    • Double-click gmer.exe to run it.
    • Let the gmer.sys driver to load if asked.
    • If it gives you a warning at program start about rootkit activity and asks if you want to run a scan... click NO.
    • Click the Rootkit tab.
    • Make sure all the boxes on the right of the screen are checked, EXCEPT for "Show All".
    • Then click the Scan button. Wait for the scan to finish.
    • Once done, click the Copy button.
    • This will copy the results to the clipboard. Open Notepad and press CTRL + V to paste the log, and save it to your desktop. Attach this log to your next reply.
    NOTE: If you're having problems with running gmer.exe, try it in Safe Mode. This tool works in Safe Mode whereas many other rootkit revealers do not.
     
  13. alexp91

    alexp91 Private E-2

    Here it is.

    Edit: Oh, and at the end of it, it said something like, 'Your computer has been modified by ROOTKIT activity!'
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Until you uninstall ALL but one antivirus program (decide which you prefer, we like AVG Free) we are not going any further. This is one of the first instructions in the READ & RUN ME for a reason. You should not have posted any logs until you have completed ALL of the instructions in the READ ME. Also you did not uninstall Viewpoint Manager as requested.

    You also need to put your system in normal startup mode using MSconfig as requested at the start of the READ & RUN ME.

    Then after you have done all of the above, attach a new MGlogs.zip file by running GetLogs.bat again.

    The hidden file AVG Anti-Rootkit may be just from another scanning type tool. It said it was a hidden driver. We shall see. But it will be much easier to figure things out once you have removed all the unnecessary redundant programs. All of these could also make it impossible to fix anything if there is a problem.

    The file probably does not even exist or it probably renames all the time and could be related to installed software (even games....especially protected games).
     
  15. alexp91

    alexp91 Private E-2

    If I only had 3 anti-virus software, as TimW had pointed out, then I removed 2 of them and only have one now (meaning that SpyBot, Ad-Aware, Comodo BOClean, and AVG Anti-Rootkit/Anti-Spyware should not be anti-virus software because I really don't know.)

    Then, here is the new log.

    If this is simply an error of it not existing or renaming, then I'm curious what's eating up the other 50% of my computer usage.

    Edit: And if I have Viewpoint Manager still, which I'm sure I deleted, I have no clue where to find it because it's no longer in the Add or Remove Programs list, or Program Files folder.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Here are all the tools you have installed that related to malware in general. I highlighted in bold black the problem areas.
    As you can see Norton/Symantec is still on your computer wasting resources and causing problems due to not only duplicate antivirus programs but duplicate firewalls because Norton 360 has a firewall and you also have PC Tools Firewall.

    No wonder you have CPU useage issues. Installing more that one (and you had at least 3 ) cause all kinds of problems and makes it very difficult to completely recover from.

    Try running the below. I'm not sure if it will work with Norton 360.
    Norton Removal Tool (SymNRT)

    Let me know what happens.


    It's gone now. It was in your previous log that I looked at.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also note that right now AVG Antisypware is also conflicting with ComodoBO Clean beacuse the 15 day trial of AVG Antispyware provides realtime blocking just like BOClean. Thus you should uninstall AVG Antispyware now. Yes I know it was requested in the READ ME but we don't know when you come here what is installed and we need your PC scanned and clean. BOClean also has no scanner.
     
  18. alexp91

    alexp91 Private E-2

    The Norton Removal tool worked well, and Norton should be out of my computer now. PC Tools was the anti-virus program I chose to keep, and I therefore deleted AVG 7.5 and Norton. I just deleted AVG Anti-Spyware, meaning AVG Anti-Rootkit is the last AVG product that I have. Should I delete this also?

    I'll upload another MGtools.zip to confirm Norton really is out.

    I have to go because it's late for how early I have to wake up, but I'll check this post the first thing tomorrow.

    Thanks a lot for the help so far. Maybe all this junk is what's making my computer usage go far above normal.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's much better but Norton is still hanging on a little.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Symantec Core LC
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    Do you use Dell Support and do you know why all the below need to be running at startup?

    Now run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: RefresherBand Class - {B24BA06E-FB7B-4757-95C2-DC01125F750E} - C:\PROGRA~1\YREFRE~1\YREFRE~1.DLL (file missing)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    O4 - HKCU\..\RunOnce: [] C:\Program Files\Internet Explorer\IEXPLORE.EXE http://www.symantec.com/techsupp/se...000001f.0000004b&c=00000082.00000045.00000119


    After clicking Fix, exit HJT.

    Now reboot.

    Now run Ccleaner!

    Are things working any better?

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created.
     
  20. alexp91

    alexp91 Private E-2

    Alright, I did all of those things and noticed my computer reboot time and log on time has increased. Here's the MGlog.zip.

    PS. I did run another AVG Anti-rootkit scan, and there is still an entry everytime I run it.

    Thanks.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you saying it is taking longer?

    Is it changing names after each reboot? Or is it changing names each time you run AVG Anti-rootkit? What is is called now?
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why are you using MSconfig when the READ ME ask you to put your system in Normal Startup mode?? You need to put your PC in normal startup mode now.

    I still see the below. Does that mean you need these?
    O4 - HKLM\..\Run: [OSCD_Creator] c:\Dell\PreODM.EXE
    O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
    O4 - HKLM\..\RunOnce: [OSCD_Creator] C:\Dell\PreODM.EXE /2
     
  23. alexp91

    alexp91 Private E-2

    I'm an idiot, first of all: I mean it's taking a shorter time (I notice improvement). Yes, the malware is changing after each reboot (I loaded AVG anti-rootkit, searched and found the malware, closed without deleting it/restarting, performed the same process, and the same malware appeared with the same name with NO restart in between), and it is currently called C:\WINDOWS\System32\Drivers\a7vjpbg7.SYS until my next reboot.

    To answer your next question, I do not know what MS Config mode is, but I'm pretty sure my computer is, by default, in normal mode, even as I type this message.

    As you asked above, I used the Windows Messenger Remover to delete the Dell programs. If I misread that, and using the Windows Messenger Remover was actually a separate step from the Dell Support question, then I do not actively use Dell Support (or know why it starts at my bootup) and am willing to remove it.

    Thanks
     
  24. alexp91

    alexp91 Private E-2

    So far today, I've noticed the speed has increased, however, throughout the whole day, my computer usage has been sitting above 50%. I literally have nothing running save this browser and my startup programs, leading me to near positively presume their is malware stealing my computer usage.

    Just wanted to point out that although there was a speed increase, I'm near positive there is still malware existing.
     
  25. alexp91

    alexp91 Private E-2

    Are there any other things I can do to remove this malware? Or does it show in the logs?

    Thanks.
     
  26. alexp91

    alexp91 Private E-2

    Yep... still have the malware, I think..
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    At this point, I'm not convinced this is malware. I'm not sure what it is for but it could be related to something you have installed. What actual malware problems are you having?

    You should know. The below is a quote right out of the first step of the READ & RUN ME
    You are not in normal startup mode, I can see that in your logs. Get into normal startup mode and then attach a new MGlogs.zip file. Also run ComboFix again and attach a new log from it.


    They were unrelated. If you don't use the Dell Support items then remove them using analyse.exe
     
  28. alexp91

    alexp91 Private E-2

    The main symptom is my computer usage randomly shoots and maintains 100% while I only have 1-2 programs running (ie. Internet Explorer, Microsoft Word). Then, it also showed a file in the AVG Anti-rootkit report.

    I placed my computer into normal setup.

    Here are the new logs.
     

    Attached Files:

  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But what process is using the CPU time?

    When you see high CPU useage, try the below.

    Download ProcessExplorer
    • Unzip it to its own folder somewhere you can locate it.
    • Now run procexp.exe by double clicking on it.
    • Let's configure some options first:
      • Click View and select Show Lower Pane. And where it says "Lower Pane View" make sure DLL's is checked.
      • Now click on iexplorer.exe (or which ever process is the hog)
      • Now also under the View menu choose "Select columns" and put a check mark on "Image Path".
    • Now click on File and then Save As. And save the process list.
    • Post it back here as an attachment.
    • also tell me how much of the CPU was being used and by which processes and threads. You can get this info by double clicking on the process that seems to be hogging CPU time. Then in the next window click the Threads tab. There is a column showing CPU use and also you can double click on the line showing I CPU useage and it will give you a Stack for the thread. What do you see in the stack.
    I'm not convinced that this is malware.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds