worm.win32.netbooster - or rootkit

Discussion in 'Malware Help (A Specialist Will Reply)' started by Lorette, Aug 2, 2008.

  1. Lorette

    Lorette Private E-2

    Having looked at the threads involving this ´worm´and also reading a (very) little on your site about rootkits, I am having similar problems on my laptop, which is a Tobshiba running windows xp professional.
    Problems are similar to what others have described - shortcuts on the desktop, ´virus alerts´which are not from AVG or other spybot, a browser hijack that is very thorough (can only access pages by going through favourites, not by typing address in the address bar), certain programmes (spybot, firefox) are disabled - this is the same in all accounts; on infected accounts (both of which have administrator privilege) the start menu is missing all of the ´my...´links, although these can be accessed through explorer; also missing are the links to `run`, control panel, help and support and search. I can´t get to the control panel through explorer, it´s missing from there as well.

    Because of the difficulty in getting to websites directly from the laptop I will need to download the programmes onto memory stick and then onto the laptop. I am very concerned that I do not infect my desktop computer with this thing as well, so just wanted a bit of advice regarding whether you think it is transmissible through a memory stick before I start at all (probably sounds like a very blond question,but I know from previous experience that you are all angels - many thanks to shadow puter dude going back to 07). Am starting to work through the steps as given, please bear with me

    Lorette
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We cannot guarantee whether the infection (or any others you may have) will not be transferred to the flashdrive and back to your other PC. Is you other PC properly protected?

    If you are really concerned, the safe way to get the programs to the problem PC is via a CD since it is read-only.

    I assume you are trying to follow the instructions in the READ & RUN ME FIRST sticky thread??
     
  3. Lorette

    Lorette Private E-2

    Thanks for the tip.

    I started working through the sticky prior to my post and one of the admin accounts becoming infected, so I think that I have completed everything in the basic housekeeping.

    I have just run SAS which caused a crash. Now that I have rebooted, there is a popup from Windows saying that the szstem has recovered froma serious error, and a log has been created. Is the information of any use to you, or should I just close that window. I will wait before continuing incase the SAS crashes again when I run it.

    Next question - my laptop does not have a burner, so I am unsure of how to get logs over to my PC safely in order to send them to you. Can I just copy type the information into a notepad file and attach that?

    With thanks

    Lorette
     
  4. Lorette

    Lorette Private E-2

    Please don't think I am bumping! I have been able to work thru the rest of the read and run me, and in doing so my browser has got freed up so I am able to post logs directly :wine

    At the same time as the problems on the browser appeared, AVG began to give threat messages for backdoor.Ntrootkit, but in a different win32 file each time. The problems started after my partner had used the laptop, so I haven't been able to get to the bottom of what may have caused it (no pun intended - or not much of one)

    I copied exe files from D: drive to my hard drive as specified for each, and started to work thru them but the only one that would run this way was MGTools so I went back and tried to install SAS directly from the disc, which worked. However, I had to run without updating because I could not reach the site directly, and the D: drive would not read a further disc I made with the zip files on. First attempt resulted in crash, but second with recommended unchecks completed.

    Spybot would not install.

    MB installed, the updates downloaded and ran without problem. I then tried spybot again, which then did install, ran, found and fixed additional problems.

    I ran Combofix as per the instructions; at stage 31 onwards a dialogue box kept on opening saying that C:\windows\system32\clbdll.dll is not a valid windows image, please check against your installation diskette.

    I then ran MGTools (again :eek: - sorry for going in the wrong order before)

    The problems seem to have resolved themselves, the desktop and browser are back to normal and the warnings have stopped popping up. However, I would very much appreciate it if you could check my logs to make sure that I am in the clear

    Yours

    Lorette
     

    Attached Files:

  5. Lorette

    Lorette Private E-2

    And the remaining log
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to stop saving files like below into your C:\Program Files folder. This folder should be used for installed programs. It is not an appropriate place to save downloads. Especially in the base folder. If you want these, move them somewhere else; otherwise, delete them.
    Code:
    2007-01-08 06:00 92,672 ----a-w C:\Program Files\killbox.exe
    2007-01-07 16:49 13,170,312 ----a-w C:\Program Files\jre-6-windows-i586.exe
    2006-08-29 15:47 7,050,552 ----a-w C:\Program Files\psa30se_en_us.exe
    2006-03-05 12:14 2,855,080 ----a-w C:\Program Files\aawsepersonal.exe
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. Lorette

    Lorette Private E-2

    Thanks for such clear instructions.

    The regedit got the success message, so it seemed to go through ok.

    Logs attached as requested.

    The non-admin accounts appear to be working fine, as does the admin account I have been using to run the cleaning procedures and fixes on. The other admin account (which was the one which first showed the virus alert problems) is only half fixed - the disabled programmes are back, and the false warnings have stopped. But the desktop is still only half back - it still says 'virus alert' next to the clock, and the right hand side of the start menu is limited to 'set programme access & defaults, connect to..., & printers and faxes', but the 'all programmes' is back and all drives are showing on windows explorer. Should I work thru the xp cleaning procedures from this account too?

    Lorette
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The cleaning procedures have to be run on th account that is having problems in order to fix it. So if you have been attaching logs while running from another user account, you need to get all of the logs while running on the problem user account. Which user account name is the one having problems?
     
  9. Lorette

    Lorette Private E-2

    dostoyevsky was the first account to show problems, then libuse 2 got the same (which I have used to run the removal procedures and it looks like it has worked on that account); libuse had the browser redirect but not the warnings or desktop and start button changes (now also fixed). Will now run removal procedures on dostoyevsky, and also on libuse just to be sure. Something to keep me busy!

    lorette
     
  10. Lorette

    Lorette Private E-2

    Here are the logs from dostoyevsky's account.

    SAS didn't find anything, Spybot found and fixed about six different things, a hijack and registry changes, one of which was the disabling of task manager.

    How did the fixes go on libuse2 (as attached 2 posts ago)?

    Lorette
     

    Attached Files:

  11. Lorette

    Lorette Private E-2

    And here are the logs from libuse's account. SAS, spybot and MB were all clear. I temporarily gave admin priviledge in order to run combofix and MGtools.

    All three accounts seem to be functioning ok, so I hope the logs put me in the clear. Thank you for your time and patience in looking at so many logs.

    Lorette
     

    Attached Files:

    Last edited: Aug 5, 2008
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are all clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combo-fix folder from combofix.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds