Rootkit :(

Discussion in 'Malware Help (A Specialist Will Reply)' started by Frogster2692, Dec 16, 2009.

  1. Frogster2692

    Frogster2692 Private E-2

    I think, I have a rootkit virus on my computer. I have had Iexplore.exe showing up randomly in my process list for about 3 months. I have tried multiple times to remove it. The last two times I thought i had removed it, but it keeps comming back. When it comes back, it slows my computer down drasticly, plays advertisement sounds in the background, tries to open IE pages and just makes me feel unsafe in general. I have run all the programs and attached the files as asked, except combofix due to being unable to download it for the site at this time.

    On a side note, I recently changed from macaffee virus scanner to the free version of avg. Also, I have been running CCleaner for about 6 months, its an amazing tool. Please Help.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Important Notice: A new version of SUPERAntiSpyware is available.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this log later.

    2. Please go to Jotti's malware scan

    (If more than one file needs scanned they must be done separately and logs posted for each one)
    • Copy the file path in the below Code box:
      Code:
      C:\WINDOWS\system32\krl32mainweq.dll
    • At the upload site, click once inside the window next to Browse.
    • Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
    • Next click Submit file
    • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
    • This will perform a scan across multiple different virus scanning engines.
    • Important: Wait for all of the scanning engines to complete.
    • Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.


    3. Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    4. Also delete all files in the below bold folder except ones from the current date (Windows will not let you delete the files from the current day).

    • C:\Documents and Settings\Owner\Local Settings\temp

    5. Now run the below:

    Running GMER to detect rootkits



    6.
    • Now go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -l C:\TDSSKiller.txt -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive called "TDSSKiller.txt" please attach this log to your next reply.

    7. Now go to this MGTools and download the new version of MGtools.exe. Overwrite your previous MGtools.exe file with this one.

    8. Now run the new MGTools.exe and attach the C:\Mglogs.zip that it generates, let me know the results from jotti and also attach logs from SAS, GMER avenger and TDSSKiller into your next reply.

    Thanks
    Kes13!
     
  3. Frogster2692

    Frogster2692 Private E-2

    A note that I've noticed in the few days it took responding to my post; When my computer starts up, the opening of Iexplore.exe slows it down, even ending process will contiune to open it every min or so, unless i also end jqs.exe, when i end that it dosn't pop up again, most of the symptoms of the advertisements, sounds, and Iexplore.exe tasks popping up go away. I've also uninstalled Internet Explorer, as a windows componet, temporarly, before I did the scans or asked for help, I would like to reinstall it.

    I also have been ending all processes starting with AVG due to, when I open it, it no longer has any active components.

    Errors that occured

    Error 1922. Service 'SASENUM' (SASENUM) could not be delete. Verify that you have sufficient privilegs to remove system services.

    SUPERAntiSpyware Application has encountered a problem and needs to close. We are sorry for the inconvenience.

    Ran RUNSAS.EXE from the program folder. It put a popup in my browser for SAS and a file called 83585d00-38e0-4780-a284-c238352f3439.exe

    Link to Jotti
    http://virusscan.jotti.org/en/scanresult/f3f99664d1fac7bf2e4a6aa28c8a83bd51a54c44

    When I Rebooted after running avenger.exe, my computer blackscreened and stalled out. I then hard restarted by holding the power button for 10 seconds, it ran check disk, restarted again and ended up back in windows.

    I tried to delete all the files in C:\Documents and Settings\Owner\Local Settings\temp but one stayed named etilqs_wn7bFNGcLspHdSiHpr3O

    My AVG came up with a new icon with a play button, it appears that all active componets are working. I will leave it until instructed otherwise. It is currently running a scan, i let it finish befor running GMER.exe
    AVG found a Trojan horse Downloader.Generic6.QDM, attached to AviPlayer.exe, which I thought I had uninstalled, I used CCleaner to uninstall it, again. Can't find a scan results or log.

    GMER.exe ran I couldn't total kill avg after the scan before I ran GMER.exe

    TDSSKiller came up with nothing so I copyed what it said into a text file and am posting it as TDSSkiller.txt

    I've also noticed that popup adds come up when I mouse over a keyword like download or virus, the adds say Vibrant at the top right corner. The popup has nothing to do with the word itself.

    Finished MGTools.exe scan. Attaching and replying now.
     

    Attached Files:

  4. Frogster2692

    Frogster2692 Private E-2

    Here is the MGTools.log 5 files per post.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good evening. Combofix is back up and running so let's give that a run now, when it asks you to install the recovery console please do so:

    Download Combofix

    This link here gives clear instructions on how to run it.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    Thanks
    Kes13!
     
  6. Frogster2692

    Frogster2692 Private E-2

    Okay, I installed combofix.exe and ran it from the desktop. When I did this, it said AVG active scanners are still running please disable all active components before continuing. I tried to disable it, tried to uninstall it, no sucess. I ran Combofix.exe with the "risk to damage the drive" because I couldn't figure out how to get rid of AVG. I would like to uninstall it and try another Virus/firewall Protection after we are done here :)

    Back to the issue at hand. When combofix.exe first started it double beeped with each error figured it was because avg was still running. I no longer see Iexplore.exe running, I am still getting the vibrant adds. WLSngS.exe and MOM.exe have been popping up since we have started this process as well as jqs.exe still being there using small amounts of cpu frequently. Logs are posted. couldn't post the AVG error log because its 6.17MB.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    WLSngS.exe >>> relates to:
    Linksys WMP110 RangePlus Wireless PCI Adapter

    MOM.exe
    Do you mean MDM.exe?

    jqs.exe >>> relates to:
    Java Quick Starter
    purpose:
    improves the initial startup time of Java applets and applications



    1. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    KILLALL::
    
    Driver::
    H8SRTd
    H8SRTd.sys
    yfofd
     
    File::           
    C:\WINDOWS\system32\drivers\H8SRTilmxmnaowm.sys
    C:\WINDOWS\system32\H8SRTnvnioetact.dll
    C:\WINDOWS\system32\H8SRTd.sys
    C:\WINDOWS\system32\H8SRTvppyafrkql.dat
    C:\WINDOWS\system32\H8SRTitairnerdo.dll
    C:\WINDOWS\system32\H8SRTnvnioetact.dll
    C:\WINDOWS\system32\H8SRTvppyafrkql.dat
    C:\WINDOWS\system32\drivers\H8SRTd.sys
    c:\windows\system32\drivers\rsoopnz.sys
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    2. Now run GMER again as it was GMER that detected the rootkit:

    Running GMER to detect rootkits


    3. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix. and GMER.

    Thanks
    Kes13!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! In user's case the below is running which is just from the ATI Grahpics Card:
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Thanks Chas.
     
  10. Frogster2692

    Frogster2692 Private E-2

    Thanks you two. I do have an ATI card, it runs 2 versions of ati2evxx.exe for some reason in my processes. Okay this is getting interesting Gmer.exe takes about an hour to scan completly. I ran it and forgot to copy the first log, ran it again made a copy. restarted my wireless connection, BSOD. I'm attaching the error report windows gave me from the recovered from a serious error. Is it possible it attached itself to AVG? one of the reasons i wanted to uninstall it is because when the full affect of the malware was happening it had running processes would not scan and would no open any tools, also it is causing problems with combofix.
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    To the bext of my knowledge and from what I can see your logs are clean. :)

    Any remaining issues about BSOD's ATI Cards or problems with avg will have to be resolved in the software forum. You can always remove avg and load another anti virus onto your machine, but I would first run the avg removal tool before doing so, again, this is not subject for the malware forum.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  12. Frogster2692

    Frogster2692 Private E-2

    Thanks for your help kas, I will refer to the software fourm for further advice.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're very welcome! safe surfing :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds