Possible Rootkit

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Noddy11, Aug 18, 2011.

  1. Noddy11

    Noddy11 Private E-2

    Hello,

    I noticed my PC started acting a little goofy a couple of days ago, being laggy loading web pages, slower than usual booting, etc, so I did an SAS complete scan but it didn't find anything. I decided to try a few rootkit scanners and they all seem to think I have something. The references to ZwConnectPort, pIofCallDriver and catchme.sys looked a little worrisome to me.

    My hard drive is encrypted with PC Guardian so I don't know if it is confusing the scanning software, or if I do actually have a rootkit. It's probably overkill, but I've attached three logs, one from GMER, one from Root Repeal and one from Trend Micro's Rootbuster. I used Radix as well, but I won't waste your time with that too.

    If you have a little time to take a quick look and advise I would really appreciate it. Btw, I had to sanitize the logs a bit, but I don't think it will interfere with anything. Thanks a lot.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. Noddy11

    Noddy11 Private E-2

    No it isn't, that's my sister's. Sorry, probably should have said that at the outset.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then this PC may have a Master Boot Record infection on the C drive. Do you have all important data backed up? And do you have your Windows XP Boot CD so that you can boot to the Recovery Console to repair the MBR?
     
  5. Noddy11

    Noddy11 Private E-2

    I noticed in some other threads that you ask for mbrcheck logs, so I'm attaching one here. Thanks.
     

    Attached Files:

  6. Noddy11

    Noddy11 Private E-2

    Ah beat me to it. You're fast!
    Yes I backed up my stuff about an hour ago, I was contemplating flatting the whole thing. I'll have to look for my Windows CD, hopefully it's around somewhere. Will the MBR repair wipe the drive, or are you asking about the backup just in case?
     
  7. Noddy11

    Noddy11 Private E-2

    Ok, so I found a CD and booted to the recovery console and did a "fixmbr", but the PC won't boot now. It says "error loading operating system". My guess is that it's probably because the encryption boot stuff got wiped. I'll have to see if there's a PC Guardian tool to fix it. On the plus side, at least there's no keystrokes for it to log any more.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! It just rewrites the Master Boot Record. Most of the time, this works just fine and all is good, but as with many recent infections, things can go wrong which is why I suggested backing up first.

    And as you have now stated, something did go wrong in your case. Sometimes this is due to have special boot records being used by various manufacturers or as you stated when special things are done to a hard disk or file system. This always complicates things and is troublesome. Due to what malware does these days, it is actually a better idea to keep a PC as close to standard, basic, Windows installation as possible to make fixing easier.

    I cannot advise you about PC Guardian ( I believe Symanted owns this now ), but you may find it easier/faster just to reinstall from scratch since you have everything backed up.
     
  9. Noddy11

    Noddy11 Private E-2

    Hi again,

    I believe you are right about the special boot record, which most likely was created by the encryption software. The fixmbr command did warn me that it was non-standard, but I did it anyway. I had a pretty good idea it was going to make the drive inaccessible, but I wasn't that bothered about it. For various reasons I have since physically destroyed the drive and will install another soon.

    I appreciate your time and help on this, and will probably be back in the next couple of days to continue the other thread I have going.

    Thanks again.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds