Rootkit Infection Removal Assistance

Discussion in 'Malware Help (A Specialist Will Reply)' started by parrotone, Nov 25, 2009.

  1. parrotone

    parrotone Private E-2

    Greetings

    My laptop has a rootkit infection. I've run all the preliminary software removal and upgrades and run the recommended scanners and have attached the logs for review. Note Super Anti Spyware didnt find any problems so I did not attach the log since I am limited to 4 uploads.

    Thanks!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note: You do not have enough memory installed to properly run Windows XP and your PC is really too old and too slow for WinXP. Your logs show the below:
    Code:
    Processor x86 Family 6 Model 8 Stepping 6 GenuineIntel ~596 Mhz 
    Total Physical Memory 256.00 MB 
    Available Physical Memory 86.99 MB
    You need a minimum of 4 times this amount. That is 1 GB which your PC probably does not support since it is so old. I assume that you have notice how dreadfully slow your system is running. What Operating System did you have before installing Windows XP? And were both hard disks C & D used a bootable devices at one time? They both have boot record infections.

    Did you notice any error messages while running MGtools? It did not run properly. Based on your logs, it looks like you have Error Mesage Type 1 shown here: Using MGtoolsand you need to apply that fix.


    Since you have a possible MBR infection. We will need to boot to the Recovery Console ( you installed it while you installed ComboFix) to remove this infection.

    Now boot to the Recovery Console and run the fixmbr to clear a Master Boot Record infection that you have.

    You can read the below to help you do this:

    http://support.microsoft.com/kb/307654


    After running the fixmbr command and boot back to normal mode, continue with the below.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -

    After clicking Fix, exit HJT.



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Nov 28, 2009
  3. parrotone

    parrotone Private E-2

    This is a PIII laptop. I think the physical RAM limit is 512MB though I only have 256MB in it. It's old but it's still good enough for what its used for. It was running fine until it was infected.

    Disk D: is a partition that was never bootable.

    When I ran MGTools the first time I received error #2 but it was the VDD error for Win 2000 which I fixed. I applied the #1 fix you recommended.

    Running MGTools the following selection was not present:
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

    Attached are the log files. The PC is running much faster than before. Thanks!

    One other thing I noticed is user account data for "HelpAssistant" which I do not believe should be on the machine. Its taking up 500MB of disk space. Can I just delete it?
    c:\documents and settings\HelpAssistant
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your MBR infection is now gone.

    What is in the below folder created on Nov 9th?
    c:\documents and settings\Deb\Local Settings\Application Data\sjblvy

    The HelpAssistant account is created automatically when a Remote Assistance session is requested and it has limited access to the computer. If there are no pending remote assistance requests, the account is supposed to be automatically deleted. However, based on the Master Boot Record infection you had, I would say this was created by the infection for its use.

    So I would go into Control Panel->User Accounts and delete the Help Assistant account.

    You could also run the below command from a command prompt window:

    net user HelpAssistant /Delete

    Then reboot and make sure the user account is really gone from the User Account form. Then delete the folder too if it still exists.
     
  5. parrotone

    parrotone Private E-2

    The folder "c:\documents and settings\Deb\Local Settings\Application Data\sjblvy" was empty. (Before I found the rootkit I had removed the "Super Antivirus Pro" virus and was trying to remove a browser hijacker. Maybe it came from one of them.)

    I dont believe we've ever used remote assistance so I am suspicious of the HelpAssistant folders. In the User Accounts there is no account named HelpAssistant. I ran the DOS command to remove the account and the folders are still there under "C:\Documents and Settings\HelpAssistant". Can this folder be deleted or do I have to do something more elaborate?

    On a side note I checked the RAM and a 128MB DIMM must not have been making contact and was not being detected by the system. After reseating both DIMMs I have 384MB and the processor is running at 750Hz where it should be. I may pick up another 256B to max it out.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then just delete this folder.

    Yes, just delete it and then empty your Recycle Bin.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. parrotone

    parrotone Private E-2

    Both directories were successfully deleted.

    Attached are the latest MGlogs.

    Note: I have been doing some other cleanup (uninstalling unused programs). I also had a problem with AVAST giving false positives so I started rescanning with a couple tools. AVAST fixed their problem so everything is good.

    The laptop is running as good as it ever has. Thanks!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds