Rootkit infection? - please help

Discussion in 'Malware Help (A Specialist Will Reply)' started by Betsyboo, Feb 7, 2010.

  1. Betsyboo

    Betsyboo Private E-2

    Hello
    I am truly sorry to post this thread - I still have another thread from over a week ago with a previous infection but I thought I was clean from that one and to be honest because I said I thought I was clean I'm not sure if I'll get a reply to the first one......

    Another user on my pc is having problems that aren't showing on my user account. Several windows open when they log on and each says that it is trying to open a different file, "You have chosen to open xxxxx.exe (or .dll etc) from pathname. Would you like to save this file? SaveFile / Cancel". We cannot access the internet from this account.

    Avast! found Win32-Rootkit-gen(RTK) which it quarantined.

    I have run your Read & Run me routine again but could not get CCCleaner to run in the dodgy account although it ran on all the others.
    SuperAntispyware, MalwarebytesAntiMalware & Mgtools all ran ok with nothing found. Tried to run RootRepeal but had to stop it after 3 hours as it seemed to be taking so long again (last time it ran for 2.5 days and still didn't finish)
    I have had a window pop-up for Download Helper 4.4.1.
    As part of the Read & Run me routine I had disabled SpywareDoctor and now I can't start it up again - don't know if this is due to malware or my stupidity!

    After the first infection last week I followed your How to Protect Yourself from Malware and have installed Comodo but I'm not sure if I'm blocking things that I should be allowing, so don't know if I'm making things worse through ignorance.

    Can you please please help me - I am not at all computer savvy and am now getting very confused. Have attached the logs that I have. THANK YOU.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Which user account did you run the scans on? Our previous thread on your user account or one of the other user accounts on this system? Because I am not seeing anything in this account.

    Why did you not give us the exact path to the file that Avast is reporting? I need to know that.

    Did you run MBAM and SAS on this "infected user account"?
     
  3. Betsyboo

    Betsyboo Private E-2

    Hi and thanks for helping me.

    I ran cccleaner on each user account but it would not run on the Katie account (I did this 3 days ago and cannot remember exactly what messages I got, sorry).

    I ran SuperAntispyware, MBAM and Combofix from the Liz (admin) account, because I thought that they would check all the files on the computer, not just those associated with the Liz account - is this correct?

    AVAST picked up Win32-Rootkit-gen(Rtk) in
    c:\windows\system32\config\systemprofile\appdata\local\av.exe.

    I still can't enable SpywareDoctor (paid-for version) - should just be able to click a button to do this, but nothing happens. SpywareDoctor has disappeared from my system tray (the one by the clock).

    The "James" user account does not load properly - just get a blue screen for ages that says "Preparing your desktop..." and then two windows, one of which says
    "Windows cannot open this file
    ie4unit.exe
    . use the web service to find the correct program
    .select a program from a list of installed programs"
    When I eventually manage to log on to this account, it says,
    "User profile not loaded correctly, temporary profile created"

    When I log on to the "Katie" and the "JakeisgaywithJames" (sorry) accounts, several windows open, each says
    "Opening xxxxxxxx.exe
    You have chosen to open xxxxxxx.exe
    which is a: exe file
    from pathname
    Would you like to save this file?
    Save file/Cancel"

    I can close all these windows but when I want to run anything from the desktop, this window pops up again. Several icons on the desktop are not showing correctly, and on the Katie desktop have been replaced by the Firefox icon. On the JakeisgaywithJames desktop, they have been replaced by the cccleaner icon.

    I am also getting the message
    "Location not available.
    c:\Documents and Settings is not accessible
    Access is denied"
    for several folders including c:\Users\All Users\Desktop
    when I use explorer.

    Sorry that this is so long, but I don't know what is important and what's not.

    Thanks again.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The malware that you did have probably corrupted a bunch of files. What I suggest you do is to log into each user account ( other than yours ) and save any important files or data onto a CD. Once you have saved what you need, remove those user account and create new ones. You should also try uninstalling Spyware Doctor and then run CCLeaner to remove any leftovers and then after a reboot, reinstall it.

    Tell me how that goes.
     
  5. Betsyboo

    Betsyboo Private E-2

    Hi TimW
    Thanks for the advice - this'll take me a while to do! I'll let you know how things are when I've done.

    Liz
     
  6. Betsyboo

    Betsyboo Private E-2

    Hi
    I have now got rid of the "Location not available" msg by disabling "show hidden files" which I hadn't done after my previous clean-up.

    Apparently the "infected" Katie user account was ok for a couple of days after my first clean-up and didn't have all these windows popping up when you logged onto it. On 6th Feb we got the msg that Microsoft.NET Framework Assistant 1.1 had been installed as an add-on, and these problems seem to have started after that.

    It is going to be a huge job to back up all the data on the infected account onto cd - can I either copy it onto my external hard drive (J:), OR do a system restore to before the Microsoft.NET was installed OR should I uninstall Microsoft.NET OR am I barking up the wrong tree?

    Thanks
    Liz
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can backup to an external drive, as long as it is only data files. Net framework should not be causing you any issues. Did you run sfc /scannow? It will check your file integrity.Just go to start / run / and type:
    sfc /scannow

    Get me the logs from running SAS and MBAM on these two troublesome user accounts and attach the logs.
     
  8. Betsyboo

    Betsyboo Private E-2

    Hi
    After your post on 9th Feb I deleted the "Jakeisgaywithjames" and the "James" user accounts. The Jakeisgaywithjames account has completely disappeared with no trace of any files that I can see. The James account SEEMS to have disappeared but the C:\Users\James folder and sub-folders are still there. Some folders have files in even though I thought I had deleted them. (The icon on the welcome screen where you would normally log on to the account has disappeared so it LOOKS as though the account no longer exists.)

    I haven't deleted the suspicious "Katie" account because I haven't had the time to copy all the data files yet, so I created a new "KT" account as a temporary measure. This has exactly the same problem as the suspicious Katie account - all the programs that load up at logon want to open in the same window, this time Nikon Viewer because that was the first one that came up and I clicked on it. Now everything wants to run in Nikon Viewer but nothing WILL run. I have managed to get Internet Explorer to run from this new logon, though.

    I had to run sfc /scannow from the Command Prompt with the path
    C:\Windows\system32>sfc /scannow
    Hope this was ok - it "did not find any integrity violations."

    I cannot run either SAS or MBAM from the Katie account because they want to open in Firefox. I tried to use explorer to find the .exe files and run them, but the same thing happened (these programs both have the Firefox icon instead of their own). I don't know how to run them in SAFE mode.

    BTW a new user account has appeared, called ASP.NET Machine Account. It is a standard user, password protected, and can only be seen from Control Panel.

    Thanks for ur help.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There is no evidence of malware on your system, so I think you have some corrupt accounts. I am going to suggest you post in the software forum to have others help you with removing user accounts and building new ones.

    I don't know what you did with the new account you created ( KT ), but if you copied over things from the Katie account, that could be the problem.

    If you need to activate the Administrators account to work out of, you can do that by going to start / programs / accessories / then right click on cmd / choose Run as Administrator and in the command prompt type:
    Net user administrator /active:yes

    Make sure you get a success message and then type:
    exit

    You should be able to now log into the Admin. account.

    BTW, you have all these accounts:
    All Users
    DEFAULT
    Default User
    jakeisgaywithjames
    JAMES
    KATIE
    LIZ
    PUBLIC
    TEMP
    TEMP.DowlingComputer.000
    TEMP.DowlingComputer.001
    TEMP.DowlingComputer"
    TOB
    Liz
    The Gay Since you are not having any malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to tahe cleaning procedures ian step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  10. Betsyboo

    Betsyboo Private E-2

    Thanks so much for all your help, I'll post in the software forum now to carry on.

    Liz
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Good luck!! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds