After all these tools are done with, then scan with Norton and it will have enough control over the system to remove all other threats.
Main Topics
Browse All TopicsDell XP laptop w/symantec corporate 10.1 received virus warning today. Surfed the above referenced name and see rootkit revealer recommendation.
Here is the text after I scaned w/revealer:
HKLM\SECURITY\Policy\Secre
HKLM\SECURITY\Policy\Secre
HKLM\SOFTWARE\INTEL\DLLUsa
HKLM\SOFTWARE\Microsoft\Wi
HKLM\SOFTWARE\Microsoft\Wi
HKLM\SOFTWARE\Microsoft\Wi
HKLM\SOFTWARE\Microsoft\Wi
HKLM\SOFTWARE\Microsoft\Wi
HKLM\SOFTWARE\Microsoft\Wi
HKLM\SOFTWARE\UAC 3/24/2009 12:04 PM 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\
HKLM\SYSTEM\ControlSet003\
C: 0 bytes Error mounting volume
Can you instruct me what to do now?
Thanks
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Just run combofix and show us the log.
Here's the link to Combofix if you like, please attach the combofix log.
Please download ComboFix by sUBs:
http://download.bleep
You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
If needed, here's the Combofix tutorial which includes the installation of the Recovery Console:
http://www.bleepin
HKLM\SOFTWARE\UAC 3/24/2009 12:04 PM 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet
HKLM\SYSTEM\ControlSet
the above registry entries are bad, running Combofix should removed its related bad files.
Sorry for my late reply, I just got back. ComboFix has removed a lot of bad things from your computer for sure. Hmm.. you have interesting things in this log, the TDSS RootKit has added the below entries in registry to disable your antivirus notifications:
[HKEY_LOCAL_MACHINE\softwa
"AntiVirusDisableNotify"=d
"UpdatesDisableNotify"=dwo
[HKEY_LOCAL_MACHINE\softwa
"DisableMonitoring"=dword:
My suggestion is to first of delete all files from c:\documents and settings\ADMINIstrator\LOC
http://www.ewido.net/en/on
Then, download ZoneAlarm free firewall and install it. It might not install in the safe mode, but download it and keep it nonetheless to install in normal mode.
Try that and let us know, what you get.
If you are able to delete the temporary files without any problems, then its good, if not download ATF Cleaner and run it from (it is designed to delete all temporary files from areas which can harbour any viruses within):
http://www.atribune.org/pu
You can also try renaming the MalwareBytes or SuperAntiSpyware files to allow installation, the virus might be checking for filenames to prevent detection or removal. You can download them again and save them with a completely different name like - jabbathehut.exe or idontlikevirus.exe or something like that.
Thanks - I'm doing a Malwarebytes scan right now.
I'll let you know what it finds.
I'm curious about the registry items that you saw:
[HKEY_LOCAL_MACHINE\softwa
"AntiVirusDisableNotify"=d
"UpdatesDisableNotify"=dwo
[HKEY_LOCAL_MACHINE\softwa
"DisableMonitoring"=dword:
Should I edit these? Or will Malware correct them?
Malwarebyes finished - found NOTHING!
Went to install Zone Alarm firewall . Won't let me "The system administrator has set policies to prevent this installation"
Reboot - won't let me boot windows
Can boot safe mode
Should I rename SuperAntiSpyware and try to install that?
Something has still got a hold.
"The system administrator has set policies to prevent this installation"
PART I: TDss RootKit removal
Step 1: Disable TDSSserv trojan driver.
Right click the My computer icon. If you are using the non classic Start menu, then right click My computer icon on your Start button menu.
Click Properties.
Click Hardware Tab.
Click Device Manager.
In the top menu, click View and click Show Hidden Drivers.
Scroll down to non Plug and Play drivers.
Click + at left.
In the list of drivers right click TDSSserv.sys or UACd.sys (Whichever is present). (If you do not find these, then skip to Step 2)
Click Disable.
Click YES for confirm.
Close all windows and reboot your computer.
PART 2:
Then execute regedit and goto the location: HKEY_LOCAL_MACHINE\SOFTWAR
PART 3:
Please copy the below into a notepad window and save it as CFScript.txt in the same folder as ComboFix.exe file (or the renamed file). Then drag this file on top of ComboFix executable and send us the log.
KILLALL::
File::
c:\wind
Registry
[HKEY_LO
"AntiVirusDisableNo
"Up
[HKEY_LOC
"DisableMo
This should take care of most the things that are creating problems as well as awaken your Symantec antivirus. Try that and let us know what you get. Do not click on ComboFix window while its running or it might stop.
I had to add another process to kill, here it is. Please read the instructions from above to find how to execute it:
KILLALL::
File::
c:\windo
c:\docume
Registr
[HKEY_L
"AntiVirusDisableNo
"Up
[HKEY_LOC
"DisableMo
Now it looks perfect!
Hmm.. the log looks normal to me except for one strange process which is still standing...c:\docume~1\ADM
If not, then I suggest using FileAssasin from within MalwareBytes Anti-Malware to kill this file permanently from your system. You can access FileAssasin by opening MalwareBytes interface and going to 'More Tools' interface. Then click on 'Run Tool' and browse to this file. Or copy and paste the file's address from above.
Do that reboot your system in normal mode. Then scan with your own Symantec antivirus and all problems should be history.
If your computer can start in normal mode now, then its good. Otherwise, we can check another bit of registry as well, because this TDSS rootkit had installed itself as a device driver, so we need to kill those entries from within registry which point to it.
HKLM\SOFTWARE\UAC - you've checked this one and its not present... GOOD
HKLM\SYSTEM\ControlSet001\
HKLM\SYSTEM\ControlSet003\
Windows will not boot in normal mode, if it doesn't find a driver for all its installed devices(http://support.mic
Hacktool rootkit is normally found on a system where hackers may have had full control over the system (http://www.symantec.com/s
I booted up the computer using ERD disk
HKLM\SYSTEM\ControlSet001\
HKLM\SYSTEM\ControlSet003\
c:\docume~1\ADMINI~1\LOCAL
I will run the file assasin now
Download Avenger (http://swandog46.geekstog
Run Avenger, copy & paste the following text in Input script Box:
Drivers to delete:
UACd.sys
Click on Execute, followed by yes on other and reboot. This will delete the driver file which is the rootkit and after that we should delete the registry key: HKLM\SYSTEM\ControlSet003\
And
OK, we need to use Registry Assasin now to kill the unwanted registry entries:
Download it from: http://www.malwarebytes.or
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_LOCAL_MACHINE\SYSTEM\
Then try to reboot. If it still goes to Safe Mode, then please run ComboFix again and send us the log. Please let me know, what you get.
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_LOCAL_MACHINE\SYSTEM\
I still can't boot normally
Here's the CF log
I see that this c:\docume~1\ADMINI~1\LOCAL
I can't thank you enough for all of your attention.
SW
Hmm.. I would suggest taking this machine off network, some basic things to do now:
1. Run MalwareBytes scan again.
2. When your computer reboots, select 'Last Known, Good Configuration' to start it off. See if it is working normally and at the first chance that it works normally, install the firewall.
3. Open msconfig and disable everything except for Windows and Antivirus to start at bootup. Saving the setting would ask you to reboot your computer, do that and let us know, if you can bootup in normal mode or not.
4. Go back to safe mode go to start->run and type msconfig. Goto boot.ini tab and make sure that "/safeboot" option is cleared.if not clear it and restart.
Try those things and let us know, what you get.
I immediately took the laptop off network a couple of days ago when the bug was detected. I am using a clean computer to contact you and download tools. Then transfer to the sick laptop with a flash drive.
I have tried Last Known, Good Configuration many times. Will this work if system restore has been shut off? This was one of the only suggestions Symantec had/has for dealing w/bugs.
I cleared everything in msconfig
/safeboot" option is cleared
I'm running MalwareBytes now
Good! The 'Last Known, Good Configuration' might not work if system restore has been shut down. It might try to pickup settings from when it was actually on.
There is a System Repair install, which is non-destructive and would restore the computer back to normal again, I don't usually advise this unless the system has been left in a difficult state by viruses:
http://www.informationweek
As per the ComboFix logs, I can't see anything harmful on your computer except for some strange entries:
- AegisI5Installer.exe
- Internet Connection Wizard,ShellNext = hxxp://www.fulldotfind.com
- c:\docume~1\ADMINI~1\LOCAL
Let me know, what you get from MalwareBytes scan. CCleaner can also be used to clean all unneeded things from registry and temporary folders. That might also help.
Good to see that the machine is normal again. I don't know what it might have been used for before with the HackTool rootkit, but it would also be worth checking a couple of other machine in your network for any possible worm infection or presence of a botnet. TrendMicro have recently released a tool for this called RUBotted, but it is still in Beta phase, so don't know about the reliability of it. Its available from:
http://www.trendsecure.com
I read about it through another thread on Experts Exchange.
Good to see that the problem is sorted and thanks for the points. I actually owe a big thank you to rpggamergirl, she was the one who introduced me to ComboFix. I had never heard of it before and always used MalwareBytes to resolve any problems and sometimes manually as well. After reading few of her posts, I learnt about this tool.
Business Accounts
Answer for Membership
by: warturtlePosted on 2009-03-24 at 12:24:57ID: 23972161
Download ComboFix and save it with some other name and run it in safe mode. Don't use mouse or keyboard while its running. Then use MalwareBytes Anti-Malware and SuperAntiSpyware to finish things off. disable your current AV when they are running.