Got some rootkit I think, log files attached

Discussion in 'Malware Help (A Specialist Will Reply)' started by dwh, Nov 27, 2007.

  1. dwh

    dwh Private E-2

    Thanks for this great service.
    I've followed the readme and all steps....

    Setup:
    Dell Latitude, about 5 years old.
    Win2k

    Symptoms:
    1. I keep seeing recurring instances of these files in the startup even though I've removed them from time to time:
    c:\WINNT\system32\xxwtt.dll
    c:\WINNT\system32\ddcyy.dll
    yayyywv.dll
    WINotify.dll

    2. When booting up, it doesn't go right to windows. I need to hit ctl-alt-del and then it boots up.

    3. Recently a new profile was created by itself. I'm not talking the windows profile but before you boot into windows there is a new profile. I think it's called the cmos profiles?? Maybe I created it myself by mistake, but not to my recollection.

    4. The Add/Remove programs from control panel doesn't work anymore. It just hangs. I read somewhere that if you move the .cpl files elsewhere you can run them. Some of them did work, but the add/remove application is broken.

    I wanted to include the logfile from the rootkitrevealer program since it turned up a couple interesting entries but your help file doesn't say where the "save" button puts the logfile and I'm not finding it anywhere :(
    So I just included a snapshot of the output which has the data in it.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach only the logs requested in the READ ME. We do not ask for a HijackThis log because it is automatically included in the MGlogs.zip file that is requested. You need to attach the below two logs from the READ ME:

    1. AVG Antispyware
    2. C:\MGlogs.zip from running MGtools.exe
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds