This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Weirdest malware I have ever seen

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, on a client's PC (Windows 2000 SP4) I found a bunch of malware which I managed to clean, but one file keeps coming back no matter what.
The file is called sdkgks.exe - if deleted it comes back with the same name and the current time/date, and it is 91,648 Bytes. It has a RUN entry in the registry (found by HiJackThis). After a restart both the file and the RUN entry are back.

I think this may be related: When I first started to work on the PC, there was an entry in the startup folder to start rcdk.exe which I cleaned, and it stayed gone or so it seemed. But after a restart I started HiJackThis very fast, and it found the same entry again. I scanned again a minute later without changing anything in between, and the entry was gone. I never found the file.

My guess is there is yet a third file involved.

The one file I found (sdkgks.exe) keeps coming back with the same name, but I found nothing at all during my google search for it.
I know the file is there because I can use the Dos Prompt to look at it, and I viewed it in Notepad (inet.dll is referenced in it, so I bet this is the cause for the popups we are getting). But Windows Explorer does not see it, even if I enabled viewing invisible and protected files.

I copied the file to my PC in a password protected ZIP file, and here it shows in Windows Explorer.

I scanned the client's PC with Trendmicro Housecall, Spybot, Adaware and Ewido, and Norton is installed. Neither of them found the file, but my home PC with AVG Antivirus identified it as "Trojan Horse Downloader.Generic.CVH".

Now I know that AVG could identify this one file, but deleting it will not help if it keeps coming back, and I don't know if AVG will detect the other components it probably has.

Any idea how to get rid of it?

I will gladly post the file inside a password protected ZIP file on my website if someone has the tools to find out how to stop it from coming back, so please let me know (should I attach it to this forum post?).

Following is my HJT log.

Thanks!

===

Logfile of HijackThis v1.99.1
Scan saved at 4:25:19 PM, on 10/6/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\LogMeIn\RaMaint.exe
C:\Program Files\LogMeIn\LogMeIn.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\igfxtray.exe
C:\WINNT\system32\hkcmd.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\LogMeIn\LogMeInSystray.exe
C:\Program Files\ewido\security suite\SecuritySuite.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\system32\cmd.exe
C:\EscKey\HiJackThis1991 050510\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [hp 1000 firmware] C:\Program Files\hp LaserJet 1000\fwdl.exe
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\LogMeInSystray.exe"
O4 - HKLM\..\Run: [winsync] C:\WINNT\system32\sdkgks.exe reg_run
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1128627991361
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = norcapdom.dom
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = norcapdom.dom
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = norcapdom.dom
O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\NavLogon.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - 3am Labs, Inc. - C:\Program Files\LogMeIn\RaMaint.exe
O23 - Service: LogMeIn - 3am Labs, Inc. - C:\Program Files\LogMeIn\LogMeIn.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
hi

this looks like a qoologic infection
its a real nasty, and incredibly difficult to remove without special tools
it is essentially a rootkit

first lets try a scanner:
Please follow the instructions provided, you may want to print out these instructions and use them as a reference.

Please download ewido security suite it is a free version of the program.
  • Install ewido security suite
  • When installing, under "Additional Options" uncheck..
    • Install background guard
    • Install scan via context menu
  • Launch ewido, there should be an icon on your desktop, double-click it.
  • The program will now open to the main screen.
  • When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
  • You will need to update ewido to the latest definition files.
    • On the left hand side of the main screen click update.
    • Then click on Start Update.
  • The update will start and a progress bar will show the updates being installed.
    (the status bar at the bottom will display ("Update successful")
If you are having problems with the updater, you can use this link to manually update ewido.
ewido manual updates

Once the updates are installed do the following:
reboot into

Safe Mode

once in safe mode:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • You will be prompted to clean the first infection.
  • Select "Perform action on all infections", then proceed.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop or a location where you can find it easily.
Close ewido security suite.

reboot back to normal windows, rescan with hijackthis, and post the new log
also post the report from the ewido scan
Hi, shortly after I wrote this I found an page somewhere talking about this one. I did use Ewido with updated definitions, but I did not run it in Safe Mode. In fact, I did not use Safe Mode (only With Networking) because the PC is bound to a domain. I did in the end create a local user but never used it. I won't be able to get back there for quite a while, so I'd just like to collect as much information about it as possible so I am prepared when I do. Can you tell me what qoologic does? How severe and dangerous is it? The one thing I noticed are one popup per click on a link, and the amazing resistance to being removed. The main question is: Will it try to spread via network or email? If it does, I should let my client know to not use the computer until I can come back. I found a tool called Find-qooligic - will that work, too?
it shows popups and popunders, transfers confidential data, downloads and executes arbitrary code and contains backdoor functionality+ rootkit functionality to hide its files.
it doesnt spread on a network though, usually it infects computers through specially constructed websites that contain various exploits of internet explorer.
find qoologic is a tool that an experienced user can use to find its files, not recommended unless you really know what to search
an ewido scan in safe mode should be enough to kill it
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI