spooldr.sys infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by Ramesh yadav, May 14, 2009.

  1. Ramesh yadav

    Ramesh yadav Private E-2

    I reinstalled xp sp3 1 week back, after which i occasionally got bluescreen with stop error. Initially i just ignored it and rebooted, and ignored the error reporting dialog too.
    But now it is frequently giving blue sreen and stop error, so yesterday after a blue screen error i rebooted windows and allowed ms error reporting console to send the report, after sending the error report internet explorer popped up and informed that this was caused due to a driver named "spooldr.sys", and is a malware.
    I ran a full scan of KIS 2009 in high security mode but it didnt find either spooldr.sys or peacom trojan. Rather it found "jwgkvsq.vmx" in F (ext hd)/recycler/S-5-3-42-2819952290-8240758988-879315005-3665/.
    It prompted for the action to be taken, and i selected to delete it, for which it asked a reboot which i allowed, but even after reboot the infection sustained and kaspesky prompted again, but its unable to remove it after several tries.
    Another thing is that kis2009 is not working properly, i mean sometimes its protection gets disabled automatically, and i am unable to activate it...
    I cant handle it so i m posting here the logs which i collected after doing "read and run me", looking for ur help...
    Sorry for not attaching mgtools log as it is stuck at this screen-


    ******************************************************************************

    32 bit Windows OS found

    Running scan with GetUnkeys.bat - 08/11/2006 by Chaslang and ShadowPuterDude

    32 bit Windows OS found
    adding: GetUnKey.txt (188 bytes security) (deflated 89%)


    Running scan with GetRunKeys.Bat - (c) 01/28/2006 By Chaslang


    NOTE: Ignore any error messages about not finding registry keys!
    Just wait for the program to finish running!!


    Will attach it as it completes the process...
     

    Attached Files:

    Last edited: May 14, 2009
  2. Ramesh yadav

    Ramesh yadav Private E-2

    Here is the mgtools log...
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

     
  4. Ramesh yadav

    Ramesh yadav Private E-2

    Thanks for responding...
    Tried that it says "access denied". I forgot to mention in my last post that Kaspersky detected it as Net-Worm.Win32.Kido.ih. In the meantime i googled for it and found KK_v3.4.7 from Kaspersky lab. It deleted that file easily.

    Yes it is always plugged in.
    That didnt help.
    Which s/w issues are u pinting at?

    I uninstalled sunjava intentionally temporarily, i will install it again after my pc becmoes clean.

    I am concerned about the bluescreens and then the error reporting telling me that "spooldr.sys" is the cause.
    I googled it to get some info and came to know that it is a rootkit and cant be detected by most of the security softwares. It disables even the Kaspersky.
    Please help me in detecting and removing this nasty thing...
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    OK...this apparently comes in via an email attachment, which is something you need to look for in your email files to delete.

    I was you to run this:
    Rootkit Revealer.

    Now
    1. Open the Windows Task Manager, use the combination of CTRL+ALT+DEL or CTRL+SHIFT+ESC.
    2. Click on the "Image Name" button to search for "Worm.Zhelatin.GQ" process by name.
    3. Select the "Worm.Zhelatin.GQ" process and click on the "End Process" button to kill it.
    Then
    Use Windows File Search Tool to Find Worm.Zhelatin.GQ Path


    1. Go to Start > Search > All Files or Folders.
    2. In the "All or part of the the file name" section, type in "Worm.Zhelatin.GQ" file name(s).
    3. To get better results, select "Look in: Local Hard Drives" or "Look in: My Computer" and then click "Search" button.
    4. When Windows finishes your search, hover over the "In Folder" of "Worm.Zhelatin.GQ", highlight the file and copy/paste the path into the address bar. Save the file's path on your clipboard because you'll need the file path to delete Worm.Zhelatin.GQ.
    Give me the path if found and tell me if the process was found.
     
  6. Ramesh yadav

    Ramesh yadav Private E-2

    Sorry for replying late.
    There is no such process as u mentioned.
    No file with such name.
    I dont think its from email as i dont use email much.
    I ran rootkit revealer, but i it hangs when i try to save the log.
    I was so annoyed of this problem that i did a clean reinstall, formatting all drives except the external hard drive (i dont have any medium to backup the data on it).
    Flashed the bios and cd drive as well.
    Everything seemed ok except Kaspersky oftenly notifying that some "unknown application is trying to access some of my installation files stored in ext hd, which is password protected", though the system is idle.
    There was no bsod after reinstall.
    So i decided to install utorrent and download torrents. within 10 minutes of running utorrent i got a bsod with same stop error, and i was astonished when windows error reporting again pointed out that "spooldr.sys" is the culprit, which is probably a malware.
    Is utorrent rogue?
    Is microsoft dumb to find spooldr.sys though nothing else is able to find it?
    How can this thing survive after a clean reinstall, with so many precautions (too many to mention) being taken by me that no malware could survive.
    Please help, this has become mysterious...
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you did a clean install, the only way to be infected would be if you then used some infected media (thumb drive, cd's etc).

    If you did not do that, then it was from something you downloaded using Utorrent, not the program itself.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds