Combofix Rootkit Problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by NVYPWR, May 25, 2010.

  1. NVYPWR

    NVYPWR Private E-2

    Yesterday I got an error while running an exe file. And after that my PC immediately restarted. After rebooting when I try to move my files in desktop I get BSOD. I tried using combofix but it give rootkit error and rebooted my PC. I checked Qoobox folder and it has quarantined C:\Windows\System32\Driver folder but the folder is empty. I tried using Gmer but when it starts to run it gives error Windows encountered an error... I looked for rootkit removing programs but none of them found any rootkit(s). What should I do now?:cry

    Note: I have avast 4.8 before opening file it has scanned with malwarebytes' and avast but no errors

    Edit: In attachment there is a part of combofix result. I suspected that line due to rootkit alert. Can you post what is the meaning of log result?
     

    Attached Files:

    Last edited: May 25, 2010
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. NVYPWR

    NVYPWR Private E-2

    It's not working! I still got a message from windows. :cry I checked everything before running program but its no use what should I do?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    * Please download TDSSKiller to your Desktop
    * Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    * Click Start > Run and copy/paste the following bold command into Run box and hit Enter.

    "%userprofile%\Desktop\TDSSKiller.exe" -v

    * Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    * When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.
     
  5. NVYPWR

    NVYPWR Private E-2

    It's strange... Combofix suspected C:\Windows\System32\Drivers folder but quarantined nothing and TDSS Killer found nothing too. And -I guess that caused by rootkit- CPU goes on %100 and drives me crazy. Anyway here is the result
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  7. NVYPWR

    NVYPWR Private E-2

    OK then I'll continue from there and post if I encounter more problems
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have an MBR infection so I need to see all the logs.
     
  9. NVYPWR

    NVYPWR Private E-2

    Combofix suspected on MBR infection before I post here. Can you explain more about MBR infection?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is a Rootkit that has infected your Master Boot Record. This is what tells you computer how to start up.
     
  11. NVYPWR

    NVYPWR Private E-2

    Hmm... I didn't have any rootkit problems before. My biggest problem was Win32 Vitro virus. It's not my fault to infect my PC. But I was lucky to detect&delete it. If I were late, my BIOS will be overtaken by that virus. I got some infected exe files but I recovered quickly those exe files. And one more thing. You want me to post my logs here right?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, attach your logs here.
     
  13. NVYPWR

    NVYPWR Private E-2

    1st result is ready. SuperAntiSpyware didn't found any rootkit(s). And I noticed now the kaspersky cleaner program you gave me slowed down when it came %60 (I guess CPU is %100 by rootkit). Lastly I'm started to feel scared because of this rootkit. It gives me creeps. And I slowly think that formatting is not the solution of this problem...
     

    Attached Files:

  14. NVYPWR

    NVYPWR Private E-2

    Re: Combofix Rootkit Problem seems to be solved

    Other logs are ready. But no rootkits this time too. And hey I followed your guide and uninstalled Messenger Plus! on my PC. I realized that there are 2 Messenger Plus! installed my computer
    -Messenger Plus!
    -Messenger Plus! 3

    And after these scans combofix has not given rootkit error too! and Gmer started to work functially!:cool. It seems I'm clean right now. I'm not sure yet. And last thing is I have some questions::confused

    -Is my MBR infection is related with BSOD Stop 0x0000000008 error?
    -Do I cleaned rootkit?
    -Is really Messenger Plus 3 (I'm suspecting 3 especially) caused all of this problem?
    -(I hope I don't have rootkits anymore) If I didn't cleaned rootkit that CPU %100 problem caused by rootkit

    Note:All logs are below except Gmer

    And sorry for doubleposting. I do it because it is very important
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I think that you may have not disabled your cd emulation software which may have been what caused the tools to report a rootkit.

    Let's just do a few final things:

    First, what is this:
    C:\Documents and Settings\user\Desktop\x8bq2d4c.exe

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Driver::
    M
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
    
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B530A9A4-1722-4D16-AAD6-AA85E3AD2ADE}]
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  16. NVYPWR

    NVYPWR Private E-2

    That exe is Gmer. You know to prevent working of gmer some malwares have tricks. I don't renamed it to gmer so no worries about it. And I'll start doing last steps. You said virtual driver in last post. Yes, I have Daemon Tools for PS2 Emulation, Nintendo Wii emulation and for some stuff :D . But I have never got rootkit problem months ago and I have daemon tools installed that time.

    I forgot to tell I'm XP user and I have 3 drives (2 internal, 1 external) and Card Reader drives (4 drives seems empty unless there is a memory card or something else)
     
  17. NVYPWR

    NVYPWR Private E-2

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    Quote:
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: eSnipBHO - {B530A9A4-1722-4D16-AAD6-AA85E3AD2ADE} - (no file)
    O23 - Service: M - Unknown owner - C:\DOCUME~1\user\LOCALS~1\Temp\M.exe (file missing)
    After clicking Fix, exit HJT.

    I don't understand clearly here. I ticked them all you given. Now should I fix them and exit?
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just put a check mark next to the ones I gave you and then hit fix, and then just x out.
     
  19. NVYPWR

    NVYPWR Private E-2

    The thing is after doing that my pc asked for reboot it is normal isn't it?

    And combofix detected presence of avast! is running. I disable it but why combofix warned me?
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just continue on.
     
  21. NVYPWR

    NVYPWR Private E-2

    It's going very weird...

    Well I have some news. First of all you were right about Daemon Tools. Thats why combofix alerted rootkit. I realized that firstly I haven't disabled Daemon Tools and run combofix and saved combofix log due to combofix rootkit alert. Secondly I have disabled DTools for that reason and run Combofix again and saved a combofix log (Note: both of logs are from CFScripted combofix). After then I used mgtools like in your last post. After all of this I ran Gmer (It worked functially with no windows error). I left the PC for doing its work but when I came I saw BSOD again! I couldn't captured a photo but I used picture from net and replaced errors with mine. Hope these are useful about my BSOD error. And In my BSOD screen there is a magenta coloured square in down-right of my monitor(That occured on my previous BSOD's too) I guess that there are no rootkits from the begining right? Is Gmer avoided by Daemon Tools? And do you know how could I get rid of this BSOD?

    Lastly I noticed that I have installed some kind of driver. It was my PS3 console. You know PS3 uses USB for charging itself and PC don't recognize controller as a normal game joystick. For this I have downloaded some kind of SixAxis Driver for my Games (And I tested it I ran perfectly). Could it be involed in BSOD?
     

    Attached Files:

    Last edited: May 27, 2010
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. And I can't find any reference to this file: awnyqfoc.sys.

    I suggest that you post in the software forum regarding your BSOD issue.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     
  23. NVYPWR

    NVYPWR Private E-2

    Ok then since no problems with malwares I'll continue from Software forum section. Thank you for your assistance from the beginning and the end :wave;)
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are quite welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds