Yikes. Persistant Rootkit

Discussion in 'Malware Help (A Specialist Will Reply)' started by Mataj, Apr 21, 2011.

  1. Mataj

    Mataj Private E-2

    Sorry to have to bother you.

    A couple of weeks ago my employee clicked on one of those email attachments saying your tracking info for your package is attached.

    We used a system restore point and everything seemed fine.

    My employee either does not know what caused the second outbreak, or won't own up to it. Combofix detects and fixes a root kit, but on reboot all of my .EXE file associations have been broken. I have to manually go in to establish the associations to run anything. Some of the icons on the desktop are distorted including the quick menu show desktop icon, the trash bin icon, and all of the shortcut arrows.

    I will post the logs and appreciate any and all assistance!
     

    Attached Files:

  2. Mataj

    Mataj Private E-2

    Last logs
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Assuming that fixed the exe associations:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now use windows explorer to find and delete:
    C:\Documents and Settings\Carol2\Local Settings\Application Data\823844su6067g748f301q48vje741lv7bwcg7wj
    C:\Documents and Settings\Carol2\Local Settings\Application Data\q45f63b3111o63c2hk0htmd5p3j4poe
    C:\Documents and Settings\All Users\Application Data\q45f63b3111o63c2hk0htmd5p3j4poe

    Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!


    Be sure to download TDSSKiller.exe (v2.4.0.0) from Kaspersky's website and not TDSSKiller.zip which appears to be an older version 2.3.2.2 of the tool.

    • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
      Vista/Windows 7 users right-click and select Run As Administrator.
    • If TDSSKiller does not run, try renaming it. To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123tdk.com).
    • Click the Start Scan button.
    • Do not use the computer during the scan
    • If the scan completes with nothing found, click Close to exit.
    • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_14.17.05_log.txt) will be created and saved to the root directory ( usually Local Disk C ).
    • Attach this log to your next message


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * TDSSKiller log
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  5. Mataj

    Mataj Private E-2

    So far so good.

    .exe repair fix complete. We will see if it pops back up.

    Fixme.reg successful.

    Deleted the files.

    Ran TDSSKILLER.exe with no results. (Log included.)
    Ran MGtools\getlogs.bat (Log included)

    Windows update is registering that auto update is disabled, under system\automatic update it looks good?

    Icons are still distorted.

    I have avoided any unnecessary rebooting as that has seemed to exacerbate the earlier problems, let me know if that is all I need to clear up the icon issues.
     

    Attached Files:

    Last edited: Apr 21, 2011
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. Try rebooting and see if the icon issue corrects itself. Tell me what issues you are still having, if any.
     
  7. Mataj

    Mataj Private E-2

    .exe file associations broken again. Had to go to folder options - file types and create an association between .exe and application to run anything again.

    Half the icons still messed up.
     
  8. Mataj

    Mataj Private E-2

    Windows auto update still cannot be enabled.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re-run Combo and get me a new log. Then do this:

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...

    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.
     
  10. Mataj

    Mataj Private E-2

    Rootkit came up again on combofix. Stuck in stage 3. Will post logs when done.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    As soon as Combo is done, re-run TDSSKiller. Then run the MBRCheck. Attach all three logs.
     
  12. Mataj

    Mataj Private E-2

    Combofix took forever - log attached.
    TDSSKiller nothing found
    MBRcheck nothing found
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download Rootkit Unhooker from HERE.
    Save it to your desktop.
    Now double-click to run RootkitUnhooker.
    Click the Report tab, then click Scan.
    Select the pages Drivers, Stealth, Files, Code Hooks. Uncheck the rest. Click OK.
    Wait till the scanner has finished and then click File, Save Report.
    Save the report somewhere where you can find it. Click Close.
    Attach the report to your next reply.
     
  14. Mataj

    Mataj Private E-2

    Any mirrors for that file that you trust? Rootkit.com is still down.

    Thanks!

    M
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    How rude!!! Ok, let's try this:

    Download Blacklight Beta.

    * Download blbeta.exe and save it to the Desktop.
    * Once saved... double click blbeta.exe to install the program.
    * Click accept agreement and Click scan
    This app too may fire off a warning from antivirus. Let the driver load.
    Wait for it to finish.
    * If it displays any items...don't do anything with them yet. Just hit exit (close)
    * It will drop a log on Desktop that starts with fsbl....big number

    Please post contents of the BlackLight log.


    Then give this second rootkit detector a run and attach the log:
    http://www.majorgeeks.com/Rootkit_Revealer_d4652.html
     
  16. Mataj

    Mataj Private E-2

    lol, had me going there. Thanks for switching the files. Here are the two reports.
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Nothing was found by those scans, plus MBRCheck sees the MBR as correct. What malware issues are you still having, if any?
     
  18. Mataj

    Mataj Private E-2

    Combofix detects root kit activity during scan
    Windows auto update cannot be enabled
    On boot association to .exe files is broken
    Half of the icons are distorted (see pic)
    Including a Root Repeal SSDT log as it seems to find a number of hooks - though I'm not sure if that indicates a problem.
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Nothing in the log indicates a problem. Let's run you through this procedure:

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator


    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif


    * Double-click on the Rkill desktop icon to run the tool.
    * If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    * A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    * If not, delete the file, then download and use the one provided in Link 2.
    * If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    * Do not reboot until instructed.

    If you are having problems running Rkill, you can download iExplore.exe or eXplorer.exe, which are renamed copies of Rkill.com, and try them instead.

    * If the tool does not run from any of the links provided, please let me know.
    Once you've gotten one of them to run then try to immediately run the following.

    Now download and Run exeHelper from Raktor

    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.

    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    If you already have them installed, be sure to update Malwarebytes and SUPERAntiSpyware before the scan!

    Now run this: Using Malwarebytes Anti-Malware

    Now run this: SUPERAntiSpyware - running & getting a log

    Now run this: Using MGtools


    Now you need to attach (See: HOW TO: Attach Items To Your Post ) the below logs created while running the above scans

    • exeHelper log
    • Malwarebytes Anti-Malware log
    • MGlogs.zip - normally it is C:\MGlogs.zip - only attach this log from MGtools.exe DO NOT attach any logs seen in the MGtools folder.
     
  20. Mataj

    Mataj Private E-2

    I ran the suggested proceedures with no change.
    New logs attached :exehelperlog.txt & MGlogs.zip
    The Mlwarebytes Anti-Malware log ran, and I printed it out; however, I can not find it on the computer. I do however find the logs ran on 4/21 (obviously outdated) I should also mention when I searched for this log file, I kept getting the same old file over and over again.
    Since I have a printout of the log, I have recreated it for you, and have attached it.
     

    Attached Files:

  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Use windows explorer to find and delete:
    C:\Documents and Settings\Carol2\Local Settings\temp\RTDHGIXIBD.exe

    Now run this online scan:
    eSet Online Scan.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds