This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Nasty Rootkit

40 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

In that case to proceed - I think it is a variant of the TDL3 rootkit and is running from one of the main system drivers

Time to work outside of windows

There is a programme that will require you to burn a Linux live cd from an ISO file. This is a full blown operating sytem and includes a browser for going on line. It runs from the CD and is not installed on your hard drive

OK then two programmes to download

FIRST

ISOBurner this will allow you to burn Dr Web ISO to a cd and make it bootable. Just install the programme, from there on in it is fairly automatic. Instructions

SECOND

Dr Web Live CD Download this and using ISOBurner burn to CD. Usage instructions are here

Having made the bootable CD set your system to boot from CD - Do you know how to do this ?
Or you could follow the steps on this page and continue through to step 7

Once Dr Web starts select Dr.Web LiveCD (Default)

When the system is loaded, check disks or folders you want to scan and press Start

If the operating system failed to configure access to your network, you can do it manually using Networks Configure Manager. Start->Settings->Networks Configure manager. This will enable you to get online if needed.

A log will be generated could you post that please
I tried this… I don't think it's mounting my disks properly because under the C Drive the only folder that it shows are the special hidden ones for the Recycle Bin and System Volume Information. I further confirmed this because when i went to do a full scan it stopped after a half second and said finished but did not scan anything. Do you have any suggestions? these annoying invisible audio ads are really starting to bug me.
I have some good news and bad news. The good news is that I can boot into safe mode now! In the registry under the branch HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ there was an entry for a driver i didnt recognize. I looked it up and it was the driver for Process Monitor from Microsoft. I deleted that program a long time ago and then realized its probably searching for that driver but can't find it, which might be why it kept blue screening. I deleted the key and what do you know, can now boot into safe mode! The bad news is that the trusty tools are still not functioning, even in safe mode. TDSSkiller just won't start. Combofix is having driver woes, 3 attempts to start in safe mode have all led to blue screens dealing with drivers, I get BAD_POOL_CALLER, IRQL_NOT_LESS_OR_EQUAL, and then "Run the driver verifier against any new or suspect drivers.. etc. What do you think I should do?
GMER has now updated the ASWmbr programme so I would like to try that again and it will produce two logs one a dat file and one a txt file. Could you zip them both and add to your next post, as I am still thinking TDL infection

Also could you update AVP and run the analysis scan again

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it
[external image: Posted Image]

Click the "Scan" button to start scan
[external image: Posted Image]

Click the "Fix" in case of infection
[external image: Posted Image]

Save the aswMBR.log to the desktop
[external image: Posted Image]

ANALYSIS


Select the Manual Disinfection tab
Press the Gather System Information button
Once done Open the last report saved folder then attach the zip file to your next post zip
The file is located at C:\Users\your name\Desktop\Virus Removal Tool\setup_9.0.0.722_05.01.2011_20-34\LOG\avptool_sysinfo.zip

[external image: Posted Image]
Thank you - OK one service has just appeared, mayhap Dr Web revealed it

  • Re-run AVPTool
  • Select the Manual Disinfection tab
  • Where it states Step 3 paste in the following disinfection script and press execute

    begin
    SetAVZPMStatus(True);
    SearchRootkit(true, true);
    SetAVZGuardStatus(True);
     DeleteService('Katchall Service');
     SetServiceStart('Katchall Service', 4);
     StopService('Katchall Service');
     DeleteFile('C:\Program Files\InventThings\Katchall Archive\KatchallService.exe');
     BC_DeleteFile('C:\Program Files\InventThings\Katchall Archive\KatchallService.exe');
     RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\Eventlog\Application\Katchall Service','EventMessageFile');
    BC_ImportDeletedList;
    ExecuteSysClean;
    BC_Activate;
    RebootWindows(true);
    end..
  • Your system will reboot on completion, if it does not please do so yourself
  • On completion please run another analysis scan and attach the zip file

[external image: Posted Image]

Masking process with PID=3944, name = ""
>> PID substitution detected (current PID=0, real = 3944)

This is the problem the running service is masked so that I can not see the identity

Download and run Process Explorer
Once running make a note of what processes are running under Explorer and let me know if you see any thing weird
I will look at the processes from the text output - to get this
In process explorer select File > Save as… and save the file to your desktop
Attach that file in your next post
The program reveal some rather interesting things, but I didn't see anything out of the ordinary under explorer except the invisble iexplore.exe files where they were prompted to connect to the audio ads and also one that connected to " SCODEF:1624 CREDAT:79873" but I don't know what that is. The txt file for explorer is attached.
OK just to let you know I have given GMER the MBR dat file to analyse and I will await a reply on that from him Looking at the text file now Run process explorer again and kill the iexplore process as per the screenshot - then try Comobfix again πŸ“ŽUntitled.png Just rebooting to install a new driver - back in a bit
Ok I tried that - combofix's progress bar gets almost full but them my computer completely freezes. I can't tell if its trying to load something or if combofix did something that windows didnt like. In safemode it appears that combofix's progress bar gets all the way to the end but it ends up in a BSOD that cites
BAD_POOL_CALLER
Just had a response from GMER - who has been looking at this thread

Could you also ask user to run :

"mbr.exe -t -s"


To do this open a command prompt by going to start > Programmes > Accessories
Select command prompt and paste in the following then hit enter
mbr.exe -t -s
Ok. that produced a log. here is that:

Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.0.6001 Disk: WDC_WD50 rev.12.0 -> Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0

device: opened successfully
user: MBR read successfully

Disk trace:
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x869631ED]<<
_asm { PUSH EBP; MOV EBP, ESP; MOV EAX, [EBP+0x8]; CMP DWORD [EAX+0x2c], 0x7; PUSH EBX; MOV EBX, [EBP+0xc]; PUSH ESI; PUSH EDI; MOV EDI, [EBX+0x60]; JNZ 0xf7; MOV ESI, [EDI+0x4]; MOV EAX, [ESI+0xc]; }
1 nt!IofCallDriver[0x8285F13D] -> \Device\Harddisk0\DR0[0x86369AC8]
3 CLASSPNP[0x88DA0745] -> nt!IofCallDriver[0x8285F13D] -> \Device\Ide\IAAStorageDevice-0[0x85614040]
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; MOV CX, 0x4; MOV BP, 0x7be; CMP BYTE [BP+0x0], 0x0; }
user & kernel MBR OK

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI