ndis.sys infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by Deadcat, Jul 13, 2010.

  1. Deadcat

    Deadcat Private E-2

    Hey,

    I have an ndis.sys infection I cannot remove. Identified with combofix. Also there are two instances of svhost running almost full time and I have internet traffic continuously. I am trying to follow your initial instructions before posting but I cannot delete qoobox that has captured several roaches.

    Would you please help me delete qoobox so I can complete all of the cleanup instructions.

    Thanks.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't need to delete the QooBox folder from ComboFix and it is better that you do not touch because you may need backups that are saved in it since you alreay ran it. Just follow the instructions in the READ & RUN ME and attach the 5 requested logs.

    Note: There are always multiple instances of svchost.exe running.
     
  3. Deadcat

    Deadcat Private E-2

    SAS had to be run 5 times for success! The first run found two trojans and deleted them but no log was generated. The second, third,and fourth crashed. The fifth was run after unchecking the two kernal items and was the only one that generated a log.

    Running XP-SP2 on emachines laptop X86. Kaspersky was disabled for all runs. After SAS deleted the two trojans the two Svhost instances that were sending somthing out over the internet stopped. Ndis is still infected.

    First three logs attached.
     

    Attached Files:

  4. Deadcat

    Deadcat Private E-2

    Last two attachments.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to put your PC into normal startup mode with MSconfig as requested in step 4 of the READ & RUN.

    Also please remove MGtools.exe from the below folder. It does not belong here and should not be run from there. You are making it looking like malware (a rootkit).

    Also do you have any disk emulation software running like Daemon Tools? If yes, you need to run step 6 of the READ & RUN ME. If not, please tell me you don't since your logs were indicating a possible MBR infection. This could however be due to the infected ndis.sys


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. Deadcat

    Deadcat Private E-2

    Sorry about the msconfig. The compuer was not putting up the usual two screens at boot. Fixed that and ran Combo. The first try would not run. Message was this is not the correct operating system. After clicking OK the next message was "The contents of folder c:\windows\erdent Hiv-backup could not be completely deleted."

    I download a fresh copy of Combo, and ran with script overlay. It ran without any problems.

    Ran MG again from correct location. Logs are attached.

    Computer is running all software without any problems. Continuous internet sending has stopped. Internet is running correctly.

    Only thing left is that the computer is running very slow but that is not what I came here for. It appears that the ndis infection is gone.

    Thank you very much for taking the time to help with this infection. I don't understand how or why nice folks like you take the time to help as much as you do.

    Thanks again for a job well done.

    Any cleanup that needs to be done?
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    The main reason for this is your lack of adequate memory in your PC. Your logs show
    Code:
    Total Physical Memory 512.00 MB 
    Available Physical Memory 138.62 MB
    You can no longer run current versions of Windows XP with so little memory. The minimum we recommend is 1 GB ( 2 times what you have ) but 2 GB is a much better idea ( 4 times what you have ). In addition your older slower style AMD processor is not helping these days ( Stepping 2 AuthenticAMD ~1592 Mhz ). Basically, times have changed.


    Your logs are clean.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds