Rootkit Virus

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Lydster, Apr 14, 2012.

  1. Lydster

    Lydster Private First Class

    Hello again! This time I'm helping my boss with his Latitude E6500 (XP-Pro SP3). He appears to have gotten some kind of Rootkit virus; one that causes all icons and programs to be hidden.

    I've seen one of these before, so I ran the following:
    > Unhide, MBAM, TDSSKiller
    > Attached are logs, including MGTools

    It appears to be running normally now, but you guys usually have a thing or two that you recommend I should do.

    I appreciate your help.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Where are the logs from running SUPERantispyware and Combofix? I would like to see those too please.



    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
     
  3. Lydster

    Lydster Private First Class

    Sorry, forgot ComboFix and SAS. I just ran these along with MBRCheck, and logs are attached.

    Something I just noticed that I didn't see before: The Programs list in the Start Menu shows lots of empty folders/invalid shortcuts (screenshot attached). I do see MS Word, for instance, in the C:\Programs folder, and I can launch an existing Word doc from the desktop, so the program is actually still on the station. So how do we get the Start/Programs menu back?

    Thanks!
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hopefully this is going to help. Let me know if it does not.

    You can restore the defaults for the Start Menu, Accessories and Administrative Tools as follows:

    Also this might be of interest to you.

    Enable "Pin to Start Menu" for Folders in Windows Vista / XP



    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O4 - HKUS\S-1-5-19\..\Run: [Update] rundll32.exe "C:\Documents and Settings\NetworkService\Application Data\Sun\Sun\kmzkybj.dll",DllRegisterServer (User 'LOCAL SERVICE')
    • O4 - HKUS\S-1-5-20\..\Run: [Update] rundll32.exe "C:\Documents and Settings\NetworkService\Application Data\Sun\Sun\kmzkybj.dll",DllRegisterServer (User 'NETWORK SERVICE')


    After clicking Fix exit HJT.


    Delete this file:

    C:\Documents and Settings\NetworkService\Application Data\Sun\Sun\kmzkybj.dll


    You need to re-run TDSSKiller and have it fix this that you previously skipped:

    • \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip

    Attach the new log please.



    Now go to this MGTools and download the new version of MGtools.exe. Overwrite your previous MGtools.exe file with this one.

    Run the new C:\MGTools.exe and attach the new C:\MGlogs.zip
     
  5. Lydster

    Lydster Private First Class

    Results:

    1) The accrestore did restore the Accessories list, but only that one. All the other Start menu items are pretty much empty.
    2) Your posted "Enable Pin to Start Menu for Folders in Windows Vista / XP" link was a duplicate of the accrestore download.
    3) The only 04-HKUS files shown on the MGTools analyse scan did not match the two you show below, so I did nothing there.
    4) The only file in C:\Documents and Settings\NetworkService\Application Data\Sun\Sun is fptjnmg.dll
    5) "\Device\Harddisk0\DR0 ( TDSS File System )" which was found with TDSSKiller doesn't have Cure as an option, so I've been skipping it. I didn't want to Delete without confirming with you this is what you mean by having it "fix" it. Just let me know on that, please.

    Attached are the MGlogs file and the TDSS log. Thank you!
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then you will have to remove them from the list.
    Yes please, delete it, then show me the new log.
    Delete it.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  7. Lydster

    Lydster Private First Class

    Hi there. I'm not sure what you mean about removing items from the Programs list. Everything? MS Office, Safari, Startup, Dell Accessories, etc, etc. How can the laptop be navigated efficiently without programs listed in the Start/All Programs menu? Is there any way to restore them as they were before the virus? Is there anything I did as far as virus removal that caused this and that I shouldn't do again? (I'm having this same problem with my boss's wife's computer, which we have open under another ticket.)

    I deleted the TDSS entry that showed during the scan. I've attached a new log.

    I deleted the dll file from the Sun folder.

    Thanks again!
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sorry, I misunderstood what you were saying.

    Restore Admin Tools Program Files Menu


    Please download this tool here

    • You will need to unzip the tool first.
    • Once you've unzipped the tool, please double-click on it to run it.
    • Click on the Restore Administrative Tools Items button.


    This one will produce the necessary shortcut links which you can cut and paste into the start menu folder
    • Download the repair.vbs file to your destop (I have attached it to this post as Repair.zip)
    • Unzip it.
    • Run the Repair.vbs
    • When it asks for a folder name title it Recovery.
    • You will be informed of the tools progress.
    • On the desktop will be a recovery folder.
    • Open the folder up.
    • Cut and Paste the links that you want to C:\documents and settings\your name\start menu

    Did that help?
     

    Attached Files:

  9. Lydster

    Lydster Private First Class

    Hi there. I was out of town all this last week. Back to these two laptops! Update:

    > Restore Admin Tools appears to have put this back into the Control Panel, although I don't see it in the Start Menu (not sure if it was there before).

    > Repair.vbs: What this appears to have done is create another copy of the C:\Programs folder. Was that the intention? If I understand you correctly, what you're saying is that I can drag shortcuts from the executable files into the C:\D&S\User\Start Menu\Programs folder. It will create shortcuts in the Start Menu that will be labeled whatever I call them, but it will not "restore" the former shortcuts. For instance, where the Microsoft Office Start Menu shortcut used to show a list like "Microsoft Office 2003" and "Microsoft Excel 2003," when I drag and drop my own shortcuts, unless renamed, they will show "Shortcut to EXCEL" and "Shortcut to OUTLOOK" etc. Then if I create new shortcuts, I would delete those that are empty now. Is that right? If this is correct, then I don't really want to shortcut to the Recovery folder; but to the folder on C that I mention above, correct? If so, then I can just discard the Recovery folder?

    > One more thing on the Start Menu: I don't see some of the "standard" shortcuts like under Accessories, "Communications" is empty. I don't see any way to shortcut to this. Also, for instance, "Games" is also still empty, and I don't know where I would find these.

    > Quick Launch Toolbar: This is still enabled but the shortcuts aren't showing on the toolbar. Must I recreate these manually as well because the "default" QL toolbar will never come back?

    > Smart HDD shortcuts: These are still on the desktop and within the Start Menu (figures *that* would stay in the Start Menu! ;-). They appear to be shortcuts to an exe file in C:\D&S\All Users\App Data which is not actually there. Do I just delete those shortcuts now?

    I appreciate all your guidance on this. I'm sort of the go-to person for everyone I know who gets a virus, and I have a feeling I'm going to come across this one again soon. In the case of the two laptops I'm working on now, they have the original program disks and product keys, so I'm considering reformatting and reinstalling. I may not have that in the future, though, so I'd like to know how far we can go to restore normal function without reformatting.

    Your insight is very welcome.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Follow step 7 and see if that helps.

    STEP 7 : Restore your shortcuts and remove any left over malicious registry keys
    You may also be interested in STEP 9: Restore your Star Menu links
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds