|
Donation/Premium |
|
 |
|
|
|
|
|
|
|
 |
 |
| View previous topic :: View next topic |
| Author |
Message |
Jaged
Cadet

 Joined: Jul 12, 2006 Posts: 3 Location: USA
|
Posted: Wed Jul 12, 2006 7:04 am Post subject: Removing an FU Rootkit |
|
|
I have ran multiple spyware programs including Spyware Doctor, Trojan Hunter, F-Secure Blacklight, and Rootkit Revealer. Spyware Doctor found a "FU Rootkit". It claimed to automatically fix the problem, but it showed up again when it rescanned after the reboot. The rootkit will not go away. None of the other spyware programs I ran found anything of interest.
Here is a log from HijackThis. I thought that might help. Could someone please tell me how to remove this rootkit from my machine once and for all.
| Quote: | Logfile of HijackThis v1.99.1
Scan saved at 11:39:13 PM, on 7/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5296.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\NCTV\bin\dm.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\System32\dmadmin.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\TrojanHunter 4.5\THGuard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\Trillian\trillian.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.steeldragonproductions.com/council/countdown.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
R3 - Default URLSearchHook is missing
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll (file missing)
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1118612237218
O17 - HKLM\System\CCS\Services\Tcpip\..\{C6034E31-ABBE-4388-AA5B-DBDAA37EA5F6}: NameServer = 64.81.79.2,216.231.41.2
O20 - AppInit_DLLs: C:\WINDOWS\system32\wmfhotfix.dll
O20 - Winlogon Notify: AutorunsDisabled - C:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Download Manager Lite Service (DownloadManagerLite) - NetCableTV - C:\PROGRA~1\NCTV\bin\dm.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
|
|
|
| Back to top |
|
 |
nosirrah
Security Expert Special Response Team
 Joined: Apr 19, 2006 Posts: 6301 Location: USA
|
Posted: Wed Jul 12, 2006 4:30 pm Post subject: |
|
|
Aimfix : http://www.jayloden.com/AIMFix.exe contains a fix for the FU rootkit . Run aimfix once in regulare mode and then a second time in safemode .
|
|
| Back to top |
|
 |
negster22
Security Expert Premium Member
 Joined: Mar 10, 2004 Posts: 5394
|
Posted: Wed Jul 12, 2006 9:27 pm Post subject: |
|
|
Hi Jaged,
It is true that a variant of FU is can accompany the AIM virus, but I don't know if that is your problem. Here are the symptoms of the aim virus see if they match your symptoms/behavior:
http://www.jayloden.com/symptoms.htm
But Fu is a rootkit which can accompany many threats and it is not clear yet if that is what you have. BlackLight can detect FU and you said that your BlackLight scan came out clean.
1. Download the kproccheck Beta2 and extract it to C:\. It will create a folder called C:\kproccheck. Please download run-kproccheck and unzip it to the C:\kproccheck folder . It is important that run-kproccheck.bat reside in that same folder as the kproccheck executable and driver (kproccheck.exe and kprocchecks.sys). Next close all windows. Open Windows Explorer and navigate to the C:\kproccheck folder. Double-click on run-kproccheck.bat to run it. It will immediately produce a log file called kproccheck.txt, in the same folder. Please copy and paste the contents of kproccheck.txt in your net reply.
2. Please download ewido anti-spyware and perform a scan in safe mode as described. Post the ewido scan report in your next reply. (Clean temp files first)
3. Download and install IceSword
IceSword is in compressed RAR file format so you will need a utility like WinRar or the open source 7-Zip to extract it
Download and extract 7-Zip
The use 7-Zip to exract IceSword to C:\Program Files\IceSword
Once IceSword is extracted, with all browser and Explorer windows closed, run IceSword
Once IceSword is open, click the Win32 Service Function on the left Menu Bar
If any red entries are found, click the blue Log Tab at the top of the screen and save the log to documents folder as service-list.txt.
Now, Click IceSword's Process Function on the left Menu Bar
If any red entries are found, click the blue Log tab at the top of the screen and save the log to documents folder as processlist.txt.
3. Please perform a Kaspersky online antivirus scan and post the scan results back here.
4. Check your Windows Updates history and see if you have installed the windows Updates which were released yesterday. If you haven't done that please do so, because the Malicious Software Removal Tool will run automatically when you install the updates. You can also run a scan here:
http://www.microsoft.com/security/malwareremove/default.mspx#run
Now post back your ewido scan report, kproccheck.txt, AimFix log and the IceSword logs if any red entries were found, and please note them.
Also, post back the Spyware Doctor log that indicates you have FU. If the logs are long, please upload them as text files using the post reply button. I will address your HJT log later. _________________ Negster22 - MS MVP - Consumer Security 2006-2008
|
|
| Back to top |
|
 |
Jaged
Cadet

 Joined: Jul 12, 2006 Posts: 3 Location: USA
|
Posted: Thu Jul 13, 2006 7:53 am Post subject: |
|
|
Here are Spyware Doctor's findings: | Quote: | FU Rootkit HKLM\SYSTEM\ControlSet002\Enum\Root\LEGACY_MSDIRECTX High
FU Rootkit HKLM\SYSTEM\ControlSet002\Enum\Root\LEGACY_MSDIRECTX## High
FU Rootkit HKLM\SYSTEM\ControlSet002\Enum\Root\LEGACY_MSDIRECTX##NextInstance High
FU Rootkit HKLM\SYSTEM\ControlSet003\Enum\Root\LEGACY_MSDIRECTX High
FU Rootkit HKLM\SYSTEM\ControlSet003\Enum\Root\LEGACY_MSDIRECTX## High
FU Rootkit HKLM\SYSTEM\ControlSet003\Enum\Root\LEGACY_MSDIRECTX##NextInstance High
FU Rootkit HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSDIRECTX High
FU Rootkit HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSDIRECTX## High
FU Rootkit HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSDIRECTX##NextInstance High |
Attached are the ewido and kproccheck logs. Icesword was a broken link, Kaspersky is running as I am typing this, and I just installed the recent windows update.
One side question. Once I get this problem fixed and my computer cleaned out, what anti spyware should I leave running in the background? I haven't been running any up until now. I have however been using Firefox and I am behind a router firewall. Keep in mind that I am a gamer and I would like to leave as much of my machine's resources available for fragging as possible while still maintaining a secure machine.
Thanks for your help so far.
Edit: Oops, I just closed the window that was running Kaspersky. Unless you think it is really necessary I am not gonna bother starting it up again. Its painfully slow.
| Description: |
|
 Download |
| Filename: |
kproccheck.txt |
| Filesize: |
9.22 KB |
| Downloaded: |
192 Time(s) |
| Description: |
|
 Download |
| Filename: |
Report-Scan-20060712-232553.txt |
| Filesize: |
333.77 KB |
| Downloaded: |
50 Time(s) |
|
|
| Back to top |
|
 |
negster22
Security Expert Premium Member
 Joined: Mar 10, 2004 Posts: 5394
|
Posted: Thu Jul 13, 2006 6:14 pm Post subject: |
|
|
Hi Jaged,
Try to click on the link in my reply for Ice Sword. It is going thru fine for me. If you can get Ice Sword to work that would be helpful, as a second check. That is one of the best antirootkit programs out there.
You can hold of on the K. scan for now.
I have to look at the logs you submitted. _________________ Negster22 - MS MVP - Consumer Security 2006-2008
|
|
| Back to top |
|
 |
Jaged
Cadet

 Joined: Jul 12, 2006 Posts: 3 Location: USA
|
Posted: Thu Jul 13, 2006 6:22 pm Post subject: |
|
|
I lied, when I went to bed I started the Kaspersky scan. It came up clean but I figured I would upload the log anyway.
I am beginning to think I don't have a rootkit at all. Spyware Doctor is the only one that seems to think I do. Everything else thinks I am clean.
Edit: I got IceSword to download after a couple of tries.... Its weird that it took multiple tries to get it to download. Anyway, I did not see any red colored entries in either section you told me to look into
Thanks again.
| Description: |
|
 Download |
| Filename: |
kaspersky.txt |
| Filesize: |
20.23 KB |
| Downloaded: |
164 Time(s) |
|
|
| Back to top |
|
 |
negster22
Security Expert Premium Member
 Joined: Mar 10, 2004 Posts: 5394
|
Posted: Thu Jul 13, 2006 7:05 pm Post subject: |
|
|
I looked at your logs and I do not see any thing awry. Dedicated rootkit programs will be better at detecting rootkits than Spyware Doctor, and those may be just strays from an infection that has been removed already.
If you want we can do this:
Download RegSearch and extract it to a folder. Now run RegSearch.exe and type msdirectx in the first line of the search box and click "OK". RegSearch will search the occurrences of that string in Registry. When the search is over, you will get a text file which contains the search results. Please copy and paste the results in your next reply.
Spyware Doctor has real time protection doesn't it? You can turn it on and look at it's consumption in task mgr or Process Explorer, to see if it is a resource hog. The best thing to do is try out a few, and check them out in Process Explorer for resource consumption. If they hook the SSDT they are generally faster and more effective because they employ kernel device drivers that monitor and intercept kernel function calls.
WinPatrol is really light on resources. Also may want to see how Windows Defender is. Both have saved me before. Now AVs provide cross protection so most critical for your security is Windows Updates, Firewall, and a great AV. Then you may also want to use a HIPs program like Process Guard:
http://www.diamondcs.com.au/processguard/
or AntiHook.
http://www.infoprocess.biz/
You can fix this in you HJT file:
R3 - Default URLSearchHook is missing
What did you disable in Autoruns?
Also remove the HotFix in ARP. If you are current on Windows Updates you do not need that. I would get rid of those items in ewido which you did not quarantine. Why did you not set ewido to quarantine those items? The cookies I would delete. _________________ Negster22 - MS MVP - Consumer Security 2006-2008
|
|
| Back to top |
|
 |
|
|
|
You can post new topics in this forum You can reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You can attach files in this forum You can download files in this forum
|
Powered by phpBB © 2001 phpBB Group
|