Need a bit of help with Rootkit

Discussion in 'Malware Help (A Specialist Will Reply)' started by Pearlybaker, Aug 15, 2012.

  1. Pearlybaker

    Pearlybaker Private E-2

    First off -thanks for your time and help. It's very appreciated.

    I went through the Read Me and ran scans as directed but still show a number of rootkit warnings on AVG and still getting warnings for:

    trojanhorse dropper.generic.c.mmi

    Before the scans AVG was showing warnings for:
    Backdoor.generic15.bhgz
    generic27.sou

    Here are the logs - Thanks in advance to anyone willing to help.
     

    Attached Files:

  2. thisisu

    thisisu Malware Consultant

  3. Pearlybaker

    Pearlybaker Private E-2

    Thanks This..

    Ran as directed - attached are logs.
     

    Attached Files:

  4. thisisu

    thisisu Malware Consultant

    • Rescan and fix with MBAM (should find c:\windows\svchost.exe)
    • Reboot
    • Rescan with TDSSKiller
    • Post logs
     
  5. Pearlybaker

    Pearlybaker Private E-2

    MBAM found the file as mentioned - here are logs.

    Thanks
     

    Attached Files:

  6. thisisu

    thisisu Malware Consultant

    Delete these two folders:
    • c:\windows\installer\{7ffe21fd-61db-08ef-9096-294f0462541a}
    • c:\users\alexis\appdata\local\{7ffe21fd-61db-08ef-9096-294f0462541a}

    __

    http://img17.imageshack.us/img17/3214/baticonvista7.gif Now run C:\MGtools\GetLogs.bat by right-mouse clicking it and then selecting Run as Administrator
    This updates all of the logs inside MGlogs.zip.
    When it is finished, attach C:\MGlogs.zip to your next message. (How to attach)
     
  7. Pearlybaker

    Pearlybaker Private E-2

    OK ran as directed - AVG still popped up a trojan horse warning. Should I have this turned off when runninbg any future scans?

    Here are logs
     

    Attached Files:

  8. thisisu

    thisisu Malware Consultant

    Yes :)

    http://img205.imageshack.us/img205/1894/otl.gif Fix items using OTL by OldTimer

    Double-click OTL.exe to run. (Vista/7 right-click and select Run as Administrator)
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Copy the text in the code box below and paste it into the http://img14.imageshack.us/img14/66/otlcustomfix.png text-field.
    Code:
    [COLOR="DarkRed"]:files[/COLOR]
    c:\windows\installer\{7ffe21fd-61db-08ef-9096-294f0462541a}
    c:\users\alexis\appdata\local\{7ffe21fd-61db-08ef-9096-294f0462541a}
    C:\programdata\Microsoft\Windows\DRM\C401.tmp
    C:\programdata\Microsoft\Windows\DRM\C402.tmp
    C:\Users\All Users\Microsoft\Windows\DRM\C401.tmp
    C:\Users\All Users\Microsoft\Windows\DRM\C402.tmp
    C:\windows\assembly\GAC_32\Desktop.ini
    C:\windows\assembly\GAC_64\Desktop.ini
    [COLOR="DarkRed"]:commands[/COLOR]
    [emptytemp]
    
    Now click the http://img3.imageshack.us/img3/407/otlrunfix.png button.
    If the fix needed a reboot please do it.
    Click the OK button (upon reboot).
    When OTL is finished, Notepad will open. Close Notepad.
    A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    Attach this log to your next message. (How to attach)

    __

    http://img406.imageshack.us/img406/3189/windowsrepair.gif Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now open Repair_Windows.exe
    • Go to the Start Repairs tab.
    • Press the Start button
    • Create a System Restore point if prompted.
    • In the Repair Options window, choose the following repairs:
      • Repair Windows Firewall
      • Repair Windows Updates
    • Place a checkmark in Restart/Shutdown System When Finished
    • Fill in the Restart System bubble
    • Now click the Start button.
    • Be patient while the tool repairs the selected items. Your computer should automatically restart when finished.

    __

    http://img97.imageshack.us/img97/8120/fss.gif Please download Farbar Service Scanner and run it on the computer with the issue.
    • Make sure all the options are checked
    • Press Scan.
    • It will create a log (FSS.txt) in the same directory the tool was run.
    • Please attach FSS.txt to your next message. (How to attach)

    __

    http://img17.imageshack.us/img17/3214/baticonvista7.gif Now run C:\MGtools\GetLogs.bat by right-mouse clicking it and then selecting Run as Administrator
    This updates all of the logs inside MGlogs.zip.
    When it is finished, attach C:\MGlogs.zip to your next message. (How to attach)
     
  9. Pearlybaker

    Pearlybaker Private E-2

    OK - no problems with any of the scans. Here are the logs.

    My kid has to do ten pushups for every post you have to make to fix her machine - keep her looking for Gossip Girl online.:major
     

    Attached Files:

  10. thisisu

    thisisu Malware Consultant

    :)

    • Download each of the 2 files below onto the desktop of the computer with the issues:
    • Now double-click each of them, one at a time, and allow each one to merge into the Windows registry.
    • Let me know if you received a successful message for both files.
    • If both were successful, reboot your computer.

    __

    http://img97.imageshack.us/img97/8120/fss.gif Rescan with Farbar Service Scanner
    Attach its latest log.

    __

    Let me know what problems remain after completing the above steps.
     
  11. Pearlybaker

    Pearlybaker Private E-2

    Thisisu- Thanks for your help.

    The registery merge was successful and the farbar logs are attached.

    Two questions:

    1 I have a bunch of desktop.ini files on desktop - can I just delete?

    2 Do you have a link for best set-up to defend without using the resource hoarding AVs?

    Thanks
     

    Attached Files:

    • FSS.txt
      File size:
      2.8 KB
      Views:
      1
  12. Pearlybaker

    Pearlybaker Private E-2

    Registry was successful - here is log.
     

    Attached Files:

    • FSS.txt
      File size:
      2.8 KB
      Views:
      2
  13. thisisu

    thisisu Malware Consultant

    Doesn't hurt to delete them but they will also go away if you perform these last steps.

    Be sure to read the How to Protect yourself from malware! thread listed below.

    If you are not having any other malware related problems, it is time to do our final steps:
    • Any programs we had you download and/or install can be removed at this time.
    • If we had you download and run ComboFix, here is how to uninstall it:
      • Press and hold the Windows key http://i1106.photobucket.com/albums/h363/debojyotidas/Windows_Logo_key.gif and then press the letter R on your keyboard.
      • This opens the Run dialog box.
      • Copy and paste the below text inside the text-field:
        • "%userprofile%\desktop\ComboFix" /uninstall
      • Now press ENTER
      • ComboFix will extract its files one last time and you should receive a notification that ComboFix has been uninstalled shortly after.
    • You can re-enable your Disk Emulation software at this time via DeFogger.
    • If we had you create or download a registry patch or "fix" script, these can be deleted at this time.
    • Go into the C:\MGtools folder and run the MGclean.bat file to remove additional traces of our tools.
    • Now we will toggle System Restore to remove any infected system restore points.
    • Lastly, here is a guide to protect you from future infections: How to Protect yourself from malware!
    • Be safe :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds