Win32/rootkit.agent.ODG trojan in Operating Memory

Discussion in 'Malware Help (A Specialist Will Reply)' started by Savoy01, Aug 20, 2009.

  1. Savoy01

    Savoy01 Private E-2

    I was infected with the Win32/rootkit.agent.ODG trojan in the operating memory, and eset could not remove it, esset tech services worked on it for over 6 hours, and had the level 2 team trying everything they could think of and could not find it.
    We have run Super antispyware, Malwarebytes, ConboFix, Gmer, Avenger, in both normal and safe mode and have been unable to find it.
    The system is also unable to run Chkdsk, Defrag or restore, along with corrupting a number of dll files in mainly Adobe programs.
    Attached are the logs requested in Read me, except for Rootrepeal which after downloading a number of times always came up with an error message, ROOTREPEAL CRASH REPORT
    -------------------------
    Windows Version: Windows XP SP3
    Exception Code: 0xc0000094
    Exception Address: 0x00409746

    Any help would be greatly appreciated!
     

    Attached Files:

    Last edited: Aug 20, 2009
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    If you cannot find it, then how do you know it is there. What is reporting it and what exactly did it say.

    I will give you something to do based on what I see in your logs.

    I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving executable and installer files here like you are doing.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: File Print FedEx Kinko's - {9566395F-43D2-4c64-B525-B501FFA276E2} - mscoree.dll (file missing)
    O3 - Toolbar: File Print FedEx Kinko's - {9566395f-43d2-4c64-b525-b501ffa276e2} - mscoree.dll (file missing)
    O8 - Extra context menu item: &Search - ?p=ZU
    O16 - DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_03) -
    O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. Savoy01

    Savoy01 Private E-2

    The Trojan is identified on ESET scans within seconds of starting the scan
    8/25/2009 6:31:14 PM Startup scanner operating memory Operating memory Win32/Rootkit.Agent.ODG trojan unable to clean
    and I have lost chkdsk, defrag, and system restore along with various error messages on mainly Adobe programs, such as corrupt file or unable to read.
    I also now have 2 recycle bins - one on my desktop and one on C :confused
    tried to remove the C drive bin but it keeps coming back

    I have cleaned up the desktop and ran MG tools and fixed the stated files.

    Tried twice in normal mode and once in safe mode to run ComboFix with the script but as soon as it would create a restore point it would crash, I gave it plenty of time thinking it may have stalled but nothing.

    Removed Windows Messenger and ran Ccleaner and MGtools the log file is attached.

    I truly appreciate all the help - Please let me know if you need any other info.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's do this a different way since you are having problems with ComboFix.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O9 - Extra button: (no name) - AutorunsDisabled - (no file)
    O9 - Extra button: (no name) - AutorunsDisabled - (no file) (HKCU)
    O18 - Protocol: AutorunsDisabled - (no CLSID) - (no file)

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now see if you ran run RootRepeal per the instructions in the READ & RUN ME.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • the log from RootRepeal if it ran
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. Savoy01

    Savoy01 Private E-2

    I was able to run HJT and delete the 3 items, then Avenger using the script,
    but Root Repeal keeps crashing, I even tried to completely deleting it, restarting and reinstalling it, but it still crashed.
    ROOTREPEAL CRASH REPORT
    -------------------------
    Windows Version: Windows XP SP3
    Exception Code: 0xc0000094
    Exception Address: 0x00409746

    Ran Ccleaner and MGtools, the logs you requested are attached.

    ESET found
    8/29/2009 1:16:51 PM Startup scanner file \\?\globalroot\systemroot\system32\vsfoceacgkoown.dll a variant of Win32/Kryptik.AHG trojan error while cleaning
    8/29/2009 1:13:34 PM Startup scanner operating memory Operating memory Win32/Rootkit.Agent.ODG trojan unable to clean

    and according to the Avenger log it was unable to delete the file.

    I have been able to reinstall a fresh version of combo fix and ran it the log is attached.

    Help! the computer is running slower than ever, programs still are having problems with error messages that files are either corrupt or unable to read and now I am also getting redirected on Google searches.

    Would replacing the memory chips help?
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes I know about this file. It was in the list of things we were trying to fix. Avenger could not remove it. That is because there are more rootkit hidden components of the infection. We normally use RootRepeal to find these so we can fix them. Your Eset program is not reporting to you the real source of the problem which is at least one hidden driver type file (a file with a similar vshoce name but ending with a .sys). We will have to try using a couple other tools to locate the real source of the problem.

    See if you can run the below and attach the logs:

    Running GMER to detect rootkits

    SysProt AntiRootkit
     
  7. Savoy01

    Savoy01 Private E-2

    Attached is the logs for both GMER and SysProt.

    Thank You for all your help, it is greatly appreciated!!!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well SysProt was of no use but GMER did find something. It did not find everything that I would expect, but this is a start. We will gues at some of the possibly driver names based on what I have seen this infection use in the past. The names are quite random.

    First please delete the current copy of ComboFix that you have on your Desktop. Then download and save this version to your Desktop: combofix.exe



    Now we need to use ComboFix again
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!

    If ComboFix does not run, we will need to make a similar fix using Avenger.
     
  9. Savoy01

    Savoy01 Private E-2

    I deleted Combofix and then downloaded the new version which would accept the script but as soon as it did a restore point an error message would come up that it had a corrupt file and I need to run Checkdisk. Checkdisk will not run from the C drive, but I was able to run it off the repair console on the reinstall CD.
    After Checkdisk I was able to run combofix which after running came up with a box requesting approval to submit the files, I approved the submission and have attached the submission.
    I ran CCleaner and downloaded the current version of MGtools and the log is attached.
    The computer is running quicker now, but when I restarted eset the start up scan now found
    9/7/2009 3:38:07 PM Startup scanner operating memory Operating memory Win32/Olmarik trojan unable to clean

    Thank You for all you help!
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to tell us exactly what files, folders or registry keys are being declared to be a problem. Names of infections are mostly of no use to us since companies make up names as they go along and they rarely describe what the infection is. And when the do describe the infection, most of the times the files or registry keys they mention are not being found.

    The only file I'm still concerned about is the below which has no properties information. Do you know what this is from? It appeared on Aug 19th.
    Code:
    "C:\WINDOWS\SYSTEM32\DRIVERS\"
    rrl.sys       Aug 19 2009       34816  "rrl.sys"
    Your logs are clean other wise.
     
  11. Savoy01

    Savoy01 Private E-2

    First off Thank You for all your help - it has been truly a learning experience.

    2 days after the last post the computer slowed way down, and I kept getting redirected in Google serches and I started getting blue screens when I tried to work in Photoshop CS4 and Bridge with Tech. error code 0x00000007B, I would reboot and the only thing any scan (ESET, Super AntiSpyware, Malwarebytes) would show was was Operating memory Win32/Olmarik trojan unable to clean in ESET.

    After getting your post yesterday, I started over with the Run & Read Me XP cleaning instruction. Super AntiSpyware, Malwarebytes both were clean, then I ran Combofix and after it finished all hell broke loose - ESET kept popping up finding all different trojans -
    Real-time file system protection C:\WINDOWS\system32\autochk.dll Win32/Rootkit.Agent.NPB trojan cleaned by deleting (after the next restart) - quarantined
    Real-time file system protection file C:\WINDOWS\SYSTEM32\VSFOCEBCMDITNW.DLL Win32/Olmarik.KW trojan cleaned by deleting - quarantined NT AUTHORITY\LOCAL SERVICE Event occurred during an attempt to access the file by the application: C:\WINDOWS\System32\ALG.EXE.
    Real-time file system protection file C:\WINDOWS\system32\autochk.dll Win32/Rootkit.Agent.NPB trojan cleaned by deleting (after the next restart) - quarantined Event occurred during an attempt to run the file by the application: C:\WINDOWS\System32\wscntfy.exe.

    On reboot checkdisk came up on its own and ran which I have could only run off CD since this started. I then reran both Super AntiSpyware, Malwarebytes, which both found many infected files - logs attached.

    I have rerun ESET, Super AntiSpyware, and Malwarebytes, All have come back clean.

    I think the system is clean but is still slow, and I thought this twice before only to have the same problems reappear.
    I would greatly appreciate it if you could review the attached new set of MGlog and let me know if I missed anything.
    Thank You again for all your help!
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As stated in the READ & RUN ME, while we are trying to fix your PC, you must only do what we ask you to do and nothing else. You must not install other software as you are making the removal process more difficult. Examples: On Sept 2nd you installed YouSendIt. On Sept 13th, you installed Comodo. Please do not install or do anything else but what we request until we are finished with your cleanup.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - AutorunsDisabled - (no file)
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [PopRock] C:\WINDOWS\TEMP\a.exe (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [autochk] rundll32.exe C:\DOCUME~1\LOCALS~1\protect.dll,_IWMPEvents@16 (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
    O4 - Startup: AutorunsDisabled
    O14 - IERESET.INF: SearchAssistant=

    After clicking Fix, exit HJT.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds