Need Help with Nasty Rootkit - SKYNET/Trojan.Download.38278

Discussion in 'Malware Help (A Specialist Will Reply)' started by wham, Jun 16, 2009.

  1. wham

    wham Private E-2

    Hello. I seem to have a particular nasty rootkit/trojan that needs special attention. I've done everything there is to do in the malware removal guide, and all the results keep coming back clean.

    The only scanners that seem to be detecting it is Dr.Web CureIt! and GMER. The problem with Dr.Web is upon deletion, they respawn once I either reboot or relaunch my browser. GMER detects rootkit activity, a hidden service, but I get the blue screen of death a few seconds after I proceed with a full scan. I also get the blue screen of death at random times while performing daily tasks on my PC, be it online or offline. On occasion, I'll even be rerouted after clicking on a desired result in a search using google.

    I tried SUPERAntiSpyware, Malwarebytes, Spyware Doctor, Spybot, all the viable online scanners i.e. Kaspersky, BitDefender, ESET, etc. but to no avail. I'll attach the results of my Dr.Web scan. I hope someone can help, thanx.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I would like to see the logs regardless of the results :)
    As mentioned I would still like to see these logs so if you could attach them into your next reply that would be great. Also most importantly of all I need to see logs from running the following:

    • Combofix ---> C:\combofix.txt
    • MGTools ----> C:\Mglogs.zip

    Thanks
    Kes
     
  3. wham

    wham Private E-2

    I disabled everything regarding Security Center because I'm trying to cut down start-up time so the results in the Malwarebytes log, I believe, are skewed. However, as per instruction, I quarantined and deleted them anyway.
     

    Attached Files:

    Last edited: Jun 19, 2009
  4. wham

    wham Private E-2

    I won't do anything until you reply, but should I run everything again to make sure it didn't respawn?
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No, let me look over your logs which I will do as soon as I get a chance, and then I can get back to you with a set of instructions. :)

    But you can do this:

    Important Notice: A new version of SUPERAntiSpyware is out.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this log later.
     
    Last edited: Jun 19, 2009
  6. wham

    wham Private E-2

    Log attached from scan with latest version.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    FYI: If things seem slow this is why:

    You need a memory upgrade.


    1. Please go to Add/remove Programs and uninstall the following old version of Java:

    • Java(TM) 6 Update 2

    Also FYI: Ad-Aware SE Professional is not as effective as SAS or MBAM which you installed during the R&R.

    Please also uninstall Spyware Doctor 6.0 if it is just a free trial.

    2. Did you knowingly install the below toolbar for internet explorer?

    If you didn't, then please also include this to our uninstall list.

    3. Can you tell me what this is?
    4. Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    KILLALL::
    
    DirLook::
    C:\Documents and Settings\Misa\LocalLow
    
    Registry::
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    5. Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    6. Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix

    7. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
    Last edited by a moderator: Jun 22, 2009
  8. wham

    wham Private E-2

    Yea, it's a fairly outdated PC. It's a backup comp and I don't plan to be on it for much longer.

    I knowingly installed winzy bar and vb4kd4t7.exe is gmer.exe randomly named because certain types of malware prevent gmer.exe from launching.

    The PC is running as well as to be expected given that it's 8 years old, lol. But yes, it seems to be running fine now.

    A "Qoobox" folder and some files, boot.bak (bak file), settings (dat file), 209270577 (file), cmldr (file) were created in C: after running ComboFix and the like. Is it now safe to delete these files/folders? Also, should I keep C:\MGtools around or can I delete that as well?
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Keep everything where it is until we have finished. Qoobox folder is paticularly important to keep because it's a backup folder...and if something is wrongly removed we can make restorations! :)
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Now we need to use ComboFix to remove a bunch of malware file(s)/folder(s)...

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    c:\windows\system32\driver.dat
    
    Folder::
    c:\program files\sys 
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    2. From your logs I see that proquota.exe is missing from the system32 directory, we will need to replace this, and to do so, please look at the below:

    Running SFC Scannow


    3. You really need to install yourself some anti virus at this point as surfing without any is leaving you wide open to attack. You can choose from our list of reccommended in the below link:

    (scroll down to section 2)

    How to Protect yourself from malware!


    4. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    5. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!

    Thanks
    Kes13!
     
  11. wham

    wham Private E-2

    Just wanted to let you know a few things before I go any further.

    I manually deleted c:\program files\sys last week and proquota.exe was quarantined when I ran Spyware Doctor. I was going to restore it when I initially saw the ComboFix log, but I wanted to check with you first. Also, since I manually deleted c:\program files\sys, is it ok to run the script without it? I'll wait for response before I proceed.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes restore it indeed :)

    Yes it won't be a problem to still include it. So go ahead and run my script.

    Thanks
    kes
     
  13. wham

    wham Private E-2

    There are 5 other infections included with proquota.exe. From what I can gather, you can't restore infections in Spyware Doctor individually. So if I want to restore one, I'll have to restore them all. However, I believe there's a possibility that the other 5 infections may be false positives. I included a log of that as well. If you determine that they are in fact false positives, I'll go ahead and restore them.
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please restore everything that Spyware Doctor removed.
    Did Spyware Doctor remove anything else prior to your running the MGLogs in message #8 on 6/25 which was slightly after the time you ran SD?

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator)

    Then attach the below logs:

    * C:\MGlogs.zip
     
  15. wham

    wham Private E-2

    I have 3 more that I'd like for you to look at in the attached log before I go ahead and restore everything, including Application.NirCmd, which I believe are ComboFix files and registry values.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to answer Kestrel13!'s question in msg # 14 and you need to attach the new log from MGtools before your thread can be continued.

    Nircmd is not a problem. It is a valid tool used by ComboFix and is just another one of the many false positives reported by Spyware Doctor.

    Please do not run Spyware Doctor again until after have been given final instructions and have completed them. Those instructions will be given to you when your PC is deemed to be clean.
     
    Last edited: Jul 7, 2009
  17. wham

    wham Private E-2

    Yea, I ran Spyware Doctor on 6/24 and quarantined the 3 entries I attached in my previous post, including Application.NirCmd "infections". I restored everything first and then ran C:\MGtools\GetLogs.bat. Sorry for the inconvenience.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to put your PC into Normal Startup mode with MSconfig as requested in step 1 of the READ & RUN ME and you need to remain in this mode.

    Then to aid in future steps it would be best to get the current version of MGtools installed and get a new log. So please do the below after getting in normal startup mode.


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\MGlogs.zip
     
  19. wham

    wham Private E-2

    Log attached.
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    good afternoon. Whilst I go over the logs could you please disable spybot search and destroy's "Teatimer" function. See below for how to do this:

    How to disable Spybot's TeaTimer

    Thanks
    Kes
     
  21. wham

    wham Private E-2

    Yea, I did as soon as MGtools finished its business.
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    thanks :) because it often interferes with the fix

    Kes
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Could you please get this: proquota.exe into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following from the quote box below:

    2. Please go to Add/remove Programs and uninstall the following software as requested in the R&R -

    • Viewpoint Media Player

    3. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    4. Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    KILLALL::
    
    DirLook::
    C:\209270577 
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    5. Attach the zipped file I requested to look at, and also the log from ComboFix.

    Thanks
    Kes
     
  24. wham

    wham Private E-2

    C:\209270577 was not deleted upon running CFscript.txt. This may have had something to do with the fact that ComboFix updated and restarted after the initial loading of the program. Also, it deleted proquota.exe as you'll see in the log. I'll run the CFscript again on your command if necessary.

    I believe this is an ewido online scanner entry.
     

    Attached Files:

  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I only wanted to take a look at it for now.

    No need yet.

    yes it is, but it's also a dead entry now.

    Will check your logs and get back to you ASAP.

    Kes
     
  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there :)

    Let's do this:


    1. Now we need to use ComboFix to kill a couple malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\WINDOWS\system32\wbem\proquota.exe
    
    Folder::
    C:\209270577
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    2. Now go to this link Using MGTools and download the new version of MGtools.exe using the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    3. Run the new MGTools.exe and attach the C:\mglogs.zip that it generates.

    4. Also please attach the log from running ComboFix ---> C:\combofix.txt

    5. Do let us know how things are running now!

    Thanks
    Kes
     
  27. wham

    wham Private E-2

    Not sure if C:\209270577 is still supposed to be there, but it is. I'm sure you'll clarify. :)
     

    Attached Files:

  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi :)

    proquota.exe is missing, to replace it please refer to the below and read it carefully.

    Running SFC Scannow

    Then you must ensure that you do the below afterwards:

    Now go to this link Using MGTools and download the new version of MGtools.exe using the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    Run the new MGTools.exe and attach the C:\mglogs.zip that it generates into your next response here.

    Thanks
    kes13!
     
  29. wham

    wham Private E-2

    Attached. :)
     

    Attached Files:

  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi :)

    1. Now we need to use ComboFix to get a file back where it should be.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    KILLALL::
    
    FCopy::
    C:\WINDOWS\system32\dllcache\proquota.exe|C:\WINDOWS\system32\proquota.exe 
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    2. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    Thanks
    Kes13!
     
  31. wham

    wham Private E-2

    New logs. :)
     

    Attached Files:

  32. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  33. wham

    wham Private E-2

    Hello. :) There are a few files left over from some of the tools that were used during the cleaning process. They are boot. bak, settings (dat file), 209270577, and cmldr. Is it ok if I manually delete these or do I have to flush them out using a more advanced method? Oh yea, also, collect.zip. That's the proquota.exe that you asked me to archive in one of the earlier steps. Can I delete that too?
     
  34. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there :)

    C:\209270577 <--- you can delete this file

    cmldr is required for the Recovery Console.

    boot.bak is a backup of the boot.ini file which is saved while installing the Recovery Console.

    settings.dat is just a left over from RootRepeal which can be deleted.

    You can safely delete the collect.zip.
     
  35. wham

    wham Private E-2

    Everything seems to be in working order. Thanks so much for your time and effort, I really do appreciate it. Hopefully I can do right by you and not get infected again anytime soon after all the hard work you've put in to help me clean up my mess, lol.

    Just wanted your opinion on one thing. Should I keep Spyware Doctor around or is it best to just stick with Malwarebytes and the like? The reason I ask is because it seems to turn up a lot of false positives and causes more harm than good. What do you think? Thanks again, Kes. :)
     
  36. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're very welcome :)

    If you're asking me what I would do, I would ditch Spyware Doctor and keep MBAM, yes. I use both MBAM and SAS on my machines.

    safe surfing :wave Take care
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds