Rootkit activity, now can't boot into Windows without BSOD

Discussion in 'Malware Help (A Specialist Will Reply)' started by kisk, Sep 26, 2010.

  1. kisk

    kisk Private E-2

    Vista SP1 x86

    Never worked on a rootkit like this before.

    Infected my MBR which I was able to restore but now I can't get into Windows, Stop [0x8e, 0xc5] (safe mode works)
    Have ruled out memory with MEMTest86+ 4.10


    For some reason, I can no longer get Windows (normal mode) to produce a dump since last night.
    Here is the winDBG code from the last dump:


    Debugging Info



    aswSP.SYS is part of AVAST 5, but I've removed it and I'm still getting BSOD'd.
    ybnly.sys was identified by MalwareBytes as Trojan.Agent


    HJT Report

    Also booted into MiniXP (Hiren's) and ran SuperAntiSpyware just for kicks and it said the Malwarebytes executable was infected... lol what is going on with this system??

    Thanks!
     
    Last edited by a moderator: Sep 26, 2010
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.

    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.


    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this aother user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:

    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. kisk

    kisk Private E-2

    Vista Home Premium SP1 x86


    Finished all scans. Logs are attached.

    Once again, I am not able to get into Windows normal mode without a bluescreen so everything was done in safe mode.

    Bluescreen bugcheck code is 0x8E (0xC5, 0x8224C329, 0x8A98391C, 0x0), however Windows is not creating a dump even though the option is enabled in the system properties dialog (Kernel Dump). In fact, nothing in safe mode will save, msconfig changes, registry changes, etc. Weird.

    SuperAntiSpyware shows a bunch of deletions from previous Combofix runs that were quarantined. There were however a few new finds, one being a .bin file.

    Malwarebytes shows clean.

    During Combofix's Stage_3 (Only Stage_1/Stage_2 show completed), I receive an error message that PEV.cfxxe has stopped working. After hitting 'Close Program' scanning continued...

    MGtools did not create any executables in the MGtools folder. Safe mode problem? Also did not zip anything. Just recieved 3 files, which I have zipped.

    Thanks for all the help.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    RenV::
    c:\program files\Camera Assistant Software for Gateway\traybar .exe
    c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqSRMon .exe
    c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif .exe
    c:\program files\Malwarebytes' Anti-Malware\mbam .exe
    c:\program files\Synaptics\SynTP\SynTPEnh .exe
    c:\program files\Windows Live\Messenger\MsnMsgr  .exe
    c:\windows\spoolsv .exe
    c:\windows\user.exe
    c:\windows\cmd    .exe
    c:\windows\spoolsv  .exe
    c:\windows\cmd     .exe
    c:\windows\cmd      .exe
    c:\windows\cmd       .exe
    c:\windows\spoolsv   .exe
    c:\windows\cmd        .exe
    c:\windows\cmd         .exe
    
    Folder::
    c:\users\Conrad\AppData\Roaming\Pizoy    
    c:\users\Conrad\AppData\Roaming\Horemi
    
    File::
    c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    idxiga.exe
    
    Registry::
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "MqqZ"=-
    "Mqqoc"=-
    "Mqqsc"=-
    "MquuN"=-
    "Mque"=-
    "MqqE0"=-
    "MquuKc"=-
    "MqqEj"=-
    "MqqEgc"=-
    "MqqEgK"=-
    "MquuKK"=-
    "MqqEg0"=-
    "MquuK0"=-
    "MqqEgj"=-
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:


    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  5. kisk

    kisk Private E-2

    Added script to Combofix as guided. After 'Stage_2 Completed', I received "PEV.cfxxe has stopped working" dialog. After closing the dialog Combofix continued all the way up till deleted the two folders. After the two folder deletion messages on Combofix the computer restarted.

    Once again, I can only get into safe mode (Normal mode BSODs), but I let this restart continue into normal mode. It BSOD'd. I restarted back into safe mode. Had to recopy the CFScript.txt file to the desktop and now I've dragged it and restarted the scan again.

    If Combofix restarts the comp again I will come back to safe mode and respond.
     
  6. kisk

    kisk Private E-2

    Ok still having issues. Ran the script again in combofix. after trying to delete the folders listed, the combofix cmd prompt said Restarting Windows....

    I brought it back into safe mode and nothing continued.

    Where do I go from here?
     
  7. kisk

    kisk Private E-2

    When running MGtools a command prompt pops up and says..


    [Intro output]
    32 bit Windows OS found
    'C:\MGtools\swreg' is not rocognized as an internal or external command, ....
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Get me a new Combo log.

    In the meantime, I want you to run an online scan:
    eSet Online Scan.

    If it finds things, run it a second time. Then a third time if it still is finding things. Attach each log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds