Spyware possible sophosrrotkit

Discussion in 'Malware Help (A Specialist Will Reply)' started by dashrender, Apr 4, 2007.

  1. dashrender

    dashrender Private E-2

    Hello all,
    I have (or rather was in the middle of) followed the instructions in the "Read and Run First" post when I ran into several problems.

    First things first:
    I'm running XP Pro SP2 with the most recent critical updates as of 2 wks ago. I'm running Panda Platinum 2006 Anti-virus/firewall. I have Lotus Notes and am using a Windows mobile device.

    Ok current issue from the RRF page: I downloaded CCleaner and installed it, but it will not run. Nothing happens at all when I click on the icon on the desktop. Furthermore the icon is not showing the correct picture, it shows the unknown program icon. This is Dell Laptop, running 512 megs RAM (after I removed the only removable extra RAM module (apparently this laptop has 512 onboard).

    So I moved on to the next step, I downloaded and tried to install Spybot and get
    Error creating registry Key:
    HKEY_CLASSES_ROOT\CLSID\{53707962-6F74-2D53-2644-206D7942484F}

    RegCreateKeyEx failed; code 1450
    Insufficient system resources exist to complete the requested service

    Click Retry to try again, Ignore to procedd anyway, or Abort to cancel installation.

    I have tried running HJT as well, both with the exe and com extentions and neither work. (a big NOTHING happens)

    I suspect that sophosrootkit might be on the machine because there is a file C:\temp\sophosrootkit.log and a few others with simular names in the temp dir. FYI, Panda does appear to have stopped it, or at least attempted to, it is listed in the log as blocked.

    Thanks for any assistance.
     
  2. dashrender

    dashrender Private E-2

    I have managed to get a HJT log after renaming HJT to test.exe.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    If you have a rootkit of any type, it is not going to show in HJT. We need a lot more than a HJT log and yours shows no malware anyway so it is of no value. If your system is low on resources, you should shutdown some applications while running the steps. Perhaps your Panda software is bringing your system to its knees.

    Do you know what the below file is listed in your HJT log? I assyme it is part of C:\Program Files\Kaseya\Agent\KaUsrTsk.exe But what exactly is this too.

    O10 - Broken Internet access because of LSP provider 'kaseyasp.dll' missing

    Is it really missing? Check for it in c:\windows\system32

    Between Panda and the below software, perhaps you are just hogging all of your system resources:
    O4 - HKLM\..\Run: [Client Access Service] "e:\Program Files\IBM\Client Access\cwbsvstr.exe"
    O4 - HKLM\..\Run: [Client Access Help Update] "e:\Program Files\IBM\Client Access\cwbinhlp.exe"
    O4 - HKLM\..\Run: [Client Access Check Version] "e:\Program Files\IBM\Client Access\cwbckver.exe" LOGIN
    O4 - HKLM\..\Run: [Client Access Express Welcome] "e:\Program Files\IBM\Client Access\cwbwlwiz.exe"
    O4 - HKLM\..\Run: [OurTech Agent Service Helper] C:\Program Files\Kaseya\Agent\KaUsrTsk.exe
    O4 - HKLM\..\Run: [EasySync Pro - LtNts4] C:\Program Files\Common Files\XCPCSync\Translators\LtNts4\NtsAgent.exe
    O4 - HKLM\..\Run: [EasySync Pro - MSWinCE2] C:\Program Files\Common Files\XCPCSync\Translators\MSWinCE2\AutoDetect.exe
    O4 - HKLM\..\Run: [EasySync Pro] C:\Program Files\Common Files\XCPCMenu.exe
     
  4. dashrender

    dashrender Private E-2

    I will check to see if that file is there or not.

    The system resources are not all used up. I disabled Panda and this made no difference.
    Most of the processes you mentioned are related to Client Access (an emulator program for use with an AS400) These are normal processes and are really only in use when you are connected (open session) to an as400.

    I'm looking for a suggestion on how to proceed to get to the next step.
    Thanks
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If they run at startup as shown, they are using some amout of resources. Some even showed running in your process list of your HJT log.

    You said you disabled Panda! How and what did you disable?

    Well I need to know about that file in the O10 line.

    Then you can run the below to check for rootkits.

    Now please download F-Secure's BlacklightBeta
    • Download fsbl.exe and save it to the Desktop.
    • Once saved... double click fsbl.exe to install the program.
    • Click accept agreement and Click scan
    • This application may trigger a warning from your antivirus. Let the driver load. Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please attach the BlackLight log.

    If Blacklight does not find anything (which I suspect will be the case) continue onto the below.


    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds