rootkit detected...? please check logs.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by insan_art, Dec 6, 2011.

  1. insan_art

    insan_art Private First Class

    Hello all at MG! It's been 11+ months since my last infection, Avast and Comodo combo seems to be working well but something may have finally got through! I knew it would in time, even with exceptionally clean surfing habits. Oh well...

    Avast detected a rootkit this morning (it "deleted" it...). I'm having no functionality issues at this time. Ran SAS & MBAM which came up clean but after a restart Avast detects the same issue so I proceeded with the rest of the Run & Read. Things *seem* to be clean, but I would feel better if you looked at my logs since I know something is probably still hiding!

    Thanks! Logs are attached! :)
     

    Attached Files:

  2. insan_art

    insan_art Private First Class

    more logs...
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't see any malware in your logs. Attach a log from Avast so we can see what it is finding. Perhaps it is just System Restore. Or maybe not even valid.


    You do need uninstal the below old version of Sun Java:
    Java(TM) 6 Update 29
     
  4. insan_art

    insan_art Private First Class

    Thank you for your reply chaslang. I caught that old Java after I posted. Sorry about that.

    Unfortunately, this is what I was afraid of. I think I "caught" the rootkit before it got bad?!? Because like 3 hours after I posted originally, it took over my system. It was booting, but otherwise I lost all functionality. It wouldn't connect to my wireless network and I couldn't open any programs. Slowed right down to a crawl and I had to manually turn of because Windows shut down wouldn't work!

    Not sure what I should do next. I had to wait until this morning to use my husbands work laptop just to get back to you because my laptop is that bad now!!!!

    OK...I'm going in the other room to boot my laptop to see if maybe this was all a false alarm....

    ....AAAND it is not. The system boots normally but after that it's not good. Avast doesn't even start up at this point. It apparently did connect to my wireless network but I have no way of knowing this is true because I cannot open Thuderbird, Firefox, or, well, anything.

    Please help! This is so discouraging - I was supposed to start a major design project yesterday and I really need the money that comes with that. Something ALWAYS seems to get in my way when I try to get work done and/or make money. AYE. Thus is life.

    I await your advice. Thanks. Hopefully I can get back on here at the library or something while my husband has this computer at work.
     
  5. insan_art

    insan_art Private First Class

    OK...I'm checking in from a friend's system. I am able to boot the system in safe mode and open programs. Tried safe mode with networking (since it seemed to be connecting in normal boot) but it wouldn't connect - in fact it wouldn't even recognize my wireless adapter.

    What scans can i run in safe mode? I remember from the last virus clean-up I did that certain ones wouldn't work in safe mode.

    Your assistance is greatly appreciated. I'm lost and broke without my computer! :(
     
  6. thisisu

    thisisu Malware Consultant

    Hello insan_art,

    I will help you with your remaining malware problems as chaslang has been very busy.

    You can run the first two scans in Safe Mode if you wish. However, Normal Mode is preferred if possible.
    The last scan should be run from Normal Mode only.

    http://img684.imageshack.us/img684/3557/tdsskiller.gif I want you to read and follow these instructions: TDSSKiller - How to run


    http://img707.imageshack.us/img707/6703/generalxpicon.gif Please download MBRCheck by clicking here and save it to your desktop.

    • Double-click on the file to run it. (Vista/7 right-click and select Run as Administrator)
    • A window will open on your desktop.
    • If an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
    • If nothing unusual is found just press Enter.
    • A .txt file named MBRCheck_mm.dd.yy_hh.mm.txt should appear on your desktop.
    • Attach this file to your next message. (How to attach)
    http://img254.imageshack.us/img254/945/baticonxp.gif Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\MGlogs.zip
     
    Last edited by a moderator: Dec 14, 2011
  7. insan_art

    insan_art Private First Class

    Wow....super sorry I never got back to you on this. Issue turned out to be a "false positive" on Avast's end:

    http://forum.avast.com/index.php?topic=89963.15

    I figured ya'll found this out and that's why I didn't hear back right away.

    Thanks!
     
  8. thisisu

    thisisu Malware Consultant

    No problem. Thanks for letting us know.

    Here are the cleanup steps if you haven't removed anything from our procedures yet:

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis if it present
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work through the below link:
    Take care and be safe! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds