It all started from WIN32/Rootkit.agent.NSF. Now I need help to get PC up to speed

Discussion in 'Malware Help (A Specialist Will Reply)' started by gramozeka, Feb 17, 2010.

  1. gramozeka

    gramozeka Private E-2

    Hello,

    I have ESET NOD32 antivirus on my computer about two weeks ago it stopped loading at start up. I looked on line for possible cause and found a couple suggestions about updating it to newer version. So, I updated. The new version was loading ok until a couple of days ago. New version was also complaining about WIN32/Rootkit.agent.NSF. I have a log. Now even new version stopped loading at start up but I can still see some processes from NOD32 running in the task manager. It can be started from start menu but finds no problems.

    At this point I tried to back up my HDD using Drive Image XML but the computer would give me blue screen during creation of HDD shadow step.

    Tried safe mode but after selecting it computer would still load in normal mode.

    I have two HDDs installed on my computer but only one is showing in disk management but both can be browsed in my computer.

    At this point I found this forum and went through XP cleaning procedures.

    I was able to run everything except Root Repeal. Running Root repeal I would get blues screen of death

    A few more trojans were found and removed.

    After running cleaning procedures I was able to boot in to safe modewhere I can view all my HDDs through disk management.

    Booting in normal mode I can not see one of my drives in disk management but can browse it in any other progrmas. Computer crushes when I try to back up HDD using Drive image XML. And "log on Icons" for users have all changed to the same picture (airplane).

    Please help.

    PS

    System:
    Windows XP professional
    Pentium 4 2.8GHz clocked to 2.94
    2GB of ram
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: It all started from WIN32/Rootkit.agent.NSF. Now I need help to get PC up to spee

    Sounds like you have many non malware related problems too, however, in order to help you with removal of any malware that exists on the machine I will need to see logs from what tools you were able to run from our procedures. Please attach them into your next reply.
     
  3. gramozeka

    gramozeka Private E-2

    Re: It all started from WIN32/Rootkit.agent.NSF. Now I need help to get PC up to spee

    Many none malware problems... sounds bad. Before this however the computer has been running pretty well

    Logs attached. I think those are all that I have, let me know if there is anything missing.

    another problem I have found that after running cleaning procedures my MS office is going through activation wizard... and I can't find the CD. If there is anything that can be done about that please let me know.

    Thanks
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: It all started from WIN32/Rootkit.agent.NSF. Now I need help to get PC up to spee

    And were you able to run MGTools.exe? I cannot give you a complete fix without that log. C:\Mglogs.zip.
     
  5. gramozeka

    gramozeka Private E-2

    Re: It all started from WIN32/Rootkit.agent.NSF. Now I need help to get PC up to spee

    Yes, sorry... I knew I forgot something
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: It all started from WIN32/Rootkit.agent.NSF. Now I need help to get PC up to spee

    Question:- What software do you have installed from symantec?

    You need to tidy up your desktop, having loose files around is an easy way to lose them and also can impact on system performance, as well as being an ideal place for malware to hide.

    Use Windows Explorer to locate and delete the following bold folders:

    Do the same for this bold file:

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this as well as the TDSSKiller log.

    Let me know how the PC is behaving.
     
  7. gramozeka

    gramozeka Private E-2

    Re: It all started from WIN32/Rootkit.agent.NSF. Now I need help to get PC up to spee

    Here are the files, there are two tdskiller logs because I have misread your instructions and run it by double clicking on it on the desk top first. and on the second run I did it through run window.

    Should I restart the computer to evaluate how it is running because @ this moment disk management still does not see second disk.

    another thing I have noticed is that when I plug in USB drive the autostart does not happen...I am pretty sure it did autostart before I did computer cleaning procedures
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: It all started from WIN32/Rootkit.agent.NSF. Now I need help to get PC up to spee

    I am not seeing any malware in your logs and TDSSKiller didn't find anything either. Any remaining problems you have and any others questions regarding non malware subjects need to be dealt with in the software forum.

    You didn't answer my question:

    Answer that and then it will be close to final steps.
     
  9. gramozeka

    gramozeka Private E-2

    Re: It all started from WIN32/Rootkit.agent.NSF. Now I need help to get PC up to spee

    I did not notice the question...sorry

    There is nothing from symantec that I use right now. However before ESET NOD32 anti-virus I had Norton. When I switched to ESET NOD32 I uninstalled Norton through Add/Remove Programs.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: It all started from WIN32/Rootkit.agent.NSF. Now I need help to get PC up to spee

    Use add/remove programs to uninstall the following if it shows:

    • Symantec KB-DocID:2003093015493306
    • Symantec Technical Support Web Controls

    Then give the Norton removal Tool a run:

    Please give the Norton Removal Tool (SymNRT) a run > reboot your machine and then run it again for good measure.

    and finally....

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  11. gramozeka

    gramozeka Private E-2

    Re: It all started from WIN32/Rootkit.agent.NSF. Now I need help to get PC up to spee

    Did all that was listed, but problems still remain and some new once discovered.

    problems that were fixed with procedures below,

    *got my safe mode back
    *antivirus does not complain about viruses anymore

    old problems that are still there:
    *when I try to back up my hdd with driveimage xml I get BSOD
    *my antivirus does not start up when windows starts
    *disk management does not see my second physical hdd but I can browse it through windows explorer.

    new problems that appeared after cleaning computer:
    *MS office wants to validate the installation again... but I can't find the original CD that was used.
    *when USB storage device is plugged in the computer does not do autorun anymore
    *when I use my USB HDD frequently computer gives me BSOD with irq_not_less_or_equal error, I fixed this by disabling system restore but a couple days later system restore reappeared and I started getting BSOD again.
    *my scanner stopped working, it try's to scan I can hear it move the photo element briefly but when on screen it says "scanning" all I get is a black page with white noise and scanner does not move, I tried reinstalling driver to no avail.

    I hope you can help me further, Thank you
     
  12. gramozeka

    gramozeka Private E-2

    Re: It all started from WIN32/Rootkit.agent.NSF. Now I need help to get PC up to spee

    sorry, I have spoken too soon

    my eset not32 anitivus just gave me this:

    2/23/2010 2:13:36 PM Startup scanner file C:\WINDOWS\System32\DRIVERS\mrxsmb.sys a variant of Win32/Rootkit.Agent.NSF trojan unable to clean

    I have a bunch of warnings like this going back to 1/27/2010

    some of the warnings reference this file:

    2/5/2010 8:20:09 AM Real-time file system protection file C:\System Volume Information\_restore{417A4476-C43C-45BB-922B-467F40C2EA14}\RP674\A0125052.sys a variant of Win32/Rootkit.Agent.NSF trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\svchost.exe.

    this is the only one that stands out:
    2/16/2010 2:56:53 PM Real-time file system protection file C:\DOCUME~1\vip\LOCALS~1\Temp\Av-test.txt Eicar test file cleaned by deleting - quarantined TW\vip Event occurred on a new file created by the application: C:\ComboFix\CF3671.cfxxe.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: It all started from WIN32/Rootkit.agent.NSF. Now I need help to get PC up to spee

    It is giving you a false positive. Because it is a legit file in it's proper location:

    It is just finding stuff in system restore. When you follow my final steps and toggle it you will not have this problem.

    Nothing to worry about.

    See this link if you are still having issues with your anti virus not loading at start up:

    Adding programs to your Startup Folder

    and any other problems you are having such as the ones you listed will have to be sorted out in another appropriate forum such as hardware/software.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds