Malware Problems and Potential rootkit

Discussion in 'Malware Help (A Specialist Will Reply)' started by Shaderyku, May 11, 2009.

  1. Shaderyku

    Shaderyku Private E-2

    Well my computer has always been iffy but today I went to burn some files to a DVD to save up some space and my DVD burner wasn't working.. Then I got it half fixed but instead it is reading the DVD burner as a CD burner.

    I have tried rebooting (obviously)
    searching for an updated driver (No new drivers)
    Uninstalling, rebooting, and reinstalling the hardware (no luck.)
    I also tried system restore but every restore point I tried failed to restore (Before I suspected malware I foolishly deleted said restore points.)

    This is probably due to having recently installed Daemon Tools Lite, as I burned a large DVD just fine recently, just before installing Daemon Tools.

    Whether or not it is relevant to my DVD burner problem I'm sure I have some malware issues and I think Super anti spyware picked up a rootkit. I've followed all the steps and am attaching all the logfiles. Thanks in advance.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    I'm sorry but you are not having problems with malware. I do have a couple things you need to do before I send you to the Software (or Hardware Forum) though.

    Uninstall the below software:
    Java 2 Runtime Environment, SE v1.4.2_15
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME


    Now we need to use ComboFix to restore some file it incorrectly deleted.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment



    Now you should complete the below to cleanup from running the cleaning procedure:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. After doing the above, you should work thru the below link:
     
  3. Shaderyku

    Shaderyku Private E-2

    Thanks for your attention, I've performed the steps given to me by you now but feel I must clear something up.

    My DVD burner problem is almost entirely better, but I thought I should bring it to your attention that I DID have a rootkit. A day or two before I posted here, AVG caught a rootkit among other things and disposed of them. Then The day I posted, I ran superantispyware and it caught and removed a rootkit, probably the same one. Also all these procedures I've run will hopefully have gotten rid of anything it left behind but I still felt I should bring it up.

    Thanks again, I've attached the log from the run of combofix with the script that you had me run.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    It is not really a rootkit. It is a trojan and you just had a left over folder that SAS removed. And MBAM removed a remaining registry key for it. You can read about the trojan in the below link:

    http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FAGENT%2EWNQ&VSect=P

    My reference to your problems not being malware were related to your DVD burner.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds