Rootkit is in control of my machine!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by BagelAnne, Sep 17, 2012.

  1. BagelAnne

    BagelAnne Private E-2

    I have a Dell Dimension Desktop running XP with SP3 and I have been battling a few bugs for 5 days now. Please help!!
    My computer only allows me to do stuff in Safe Mode otherwise it just freezes.
    In safe mode I first scanned with SuperAntiSpyware Couldn't update it.
    Found trojan.Agent/Gen.Downloader and 254 tracking cookies.
    I tried to run GMER but got the BSOD.
    Malware bytes found 100 instances of PUP.MyWebSearch

    I ran Remove Fake Antivirus and was then able to update SuperAntiSpyware.'
    Found Trojan.Agent/Gen-Nullo
    Went back to normal mode---Still very slow but better
    Ran ESET. Found Win32/Toolbar.Widgi application and Adware.WBug.A
    Spybot found minibug
    aswMBR ran partially then froze untl I ran Rkill first and tried it again
    Found module C\Windows\System32\Drivers\dxgthk.sys Suspicious and
    C\Windows\System32\Drivers\ntdl.dll Suspicious plus 2 other red items.
    When I checked to ixMR, got another BSOD
    Bootkit Remover a rootkit
    TDSSKiller found and neutralize Rootkit.boot.Pihar.c
    Combofix found nothing.
    In Normal mode, ESET found 7 icluding installCore.D and several varieties of Olmarik AK trojan.
    Boot-cleaner "unknown Boot code..."
    Malware bytes would not update
    Rootkit buster found 31 operating system hoods but unable to fix any
    Still not working right.
    What is there left to do???
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. BagelAnne

    BagelAnne Private E-2

    Thanks Tim.
    I see you have tools there that are new to me.
    I am on it!!!
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Attach any logs you can produce.
     
  5. BagelAnne

    BagelAnne Private E-2

    Tim,
    I followed your advice and all looks to be good at this point. I will save the logs in case after a week or so there are any more issues.
    Besides all that was recommended I ran HJT this morning and it found "Side Step"
    When I removed that last piece, things went back to normal.
    Thanks for your prompt reply and especially your follow-ul email
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know. You still may need to attach the logs because there still may be traces of the infection on your system.
     
  7. BagelAnne

    BagelAnne Private E-2

    Here they are, if you are not too busy
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    So far so good. Please attach the log from running MGTools --- C:\MGLogs.zip.
     
  9. BagelAnne

    BagelAnne Private E-2

    Here it is
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks good. :)

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  11. BagelAnne

    BagelAnne Private E-2

    Thanks for everything!!!
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds