Srizbi BOT removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by ydlev, Jun 17, 2008.

  1. ydlev

    ydlev Private E-2

    Our IP was blacklisted by CBL (composite blocking list). The message on their site reads:

    ATTENTION: This IP is infected with, or NATting for a computer infected with a high volume spam sending trojan - it is participating in a botnet.
    This is the Srizbi BOT
    You need to patch your system and then fix/remove the trojan. Do this before delisting, or you're most likely to be listed again almost immediately.
    If this IP is a NAT firewall/gateway, you MUST configure the NAT to prevent outbound port 25 connections to the Internet except from your real mail servers.

    I patched Port 25 in our firewall. Now I need to remove Srizbi. I scanned PC's with on-line scanners, trial versions of several software claiming to be capable to do it, and finally did the "Windows XP Cleaning Procedure" posted on this site. Nothing was found.

    Any ideas?
    Thank you.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    If you ran the READ & RUN ME and still need help, you need to attach the 4 logs that were requested in the procedure.
     
  3. ydlev

    ydlev Private E-2

    Three log files attached. Thank you.
     

    Attached Files:

  4. ydlev

    ydlev Private E-2

    One more log file attached. Thank you.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are not showing this infection but we do need to run a rootkit scan since it can hide like that. Also we have a few other things to do and we will also put in some fixes for Srizbi just in case it is still hiding.


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 2
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2_05
    Java 2 Runtime Environment, SE v1.4.2_06
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) SE Runtime Environment 6 Update 1

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
    O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run this: Running GMER to detect rootkits

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below logs:
    • C:\ComboFix.txt
    • the GMER log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. ydlev

    ydlev Private E-2

    Did as instructed.
    Fixme.reg added to registry ok.
    The logs are attached.
    After I finished, I opened Outlook. Then chacked our firewall log (will upload in the next post). This PC IP xx.x.x.130 started sending spam to our server IP xx.xxx.xx.100. It only does it when Outlook is open.
    The firewall port 25 is patched so the spam doesn't get out (I think). Maybe it bounces back because I got 700+ spam emails in the Outlook.
    Maybe it is not srizbi? How does CBL know it's srizbi?

    Thank you for your help.
     

    Attached Files:

  7. ydlev

    ydlev Private E-2

    Firewall log pic attached.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please goto this link Windows Update and install all of the required Windows Updates and also make sure you install all updates for Outlook. You can skip the Windows XP SP3 and IE7 updates if you do not wish to do them but I want to make sure your system is fully patched. If you use Custom install instead of Express you will have more control over what gets updated.
     
  9. ydlev

    ydlev Private E-2

    Did all the updates. Still firewall log shows spam going out from this PC.
    Any suggestions?
    Thank you.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds