Jump to content

Rootkit.Agent that will not go away


Recommended Posts

Hello all. I hope you are well and are able to assist me.

My computer was infected. Not sure how, but obviously that is not important. I have been working closely with the Time Warner Cable security techs following the programs and instructions on this page - http://www.twccarolinas-security.com/

For the past 4 days we have run 5-10 scans a day with every single program.

Here is what I have found over and over -

1) Run paid version of AVG - updated multiple times a day and run multiple times a day - finds nothing

- also do AVG Rootkit scan - finds nothing

2) Run a-squared program multiple times a day - deep scan - finds nothing

3) Run SuperAntiSpyware program multiple times a day - deep scan - finds nothing

4) Run aswar root kit tool - finds nothing

5) Run Malwarebytes multiple times a day and it finds one problem - C:\WINDOWS\system32\drivers\hbmkfoja.sys (Rootkit.Agent) -> No action taken.

Try to delete - wont do it

Try to Quarantine -wont do it

Try to delete on reboot - says it does it - but comes back.

Any help would be greatly appreciated. Below and attached is my mbam-log

---------------------

Malwarebytes' Anti-Malware 1.44

Database version: 3519

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

1/8/2010 1:48:26 PM

JA1.8.10_mbam-log-2010-01-08 (13-46-32)

Scan type: Full Scan (C:\|)

Objects scanned: 251439

Time elapsed: 1 hour(s), 26 minute(s), 29 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 1

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

C:\WINDOWS\system32\drivers\hbmkfoja.sys (Rootkit.Agent) -> No action taken.

-------------

THANK YOU ALL for any help you can provide.

James

JA1.8.10_mbam_log_2010_01_08__13_46_32_.txt

Link to post
Share on other sites

Hi,

Download OTL to your desktop.

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under the Custom Scan box paste this in

    netsvcs
    msconfig
    safebootminimal
    safebootnetwork
    activex
    drivers32
    %SYSTEMDRIVE%\*.exe
    %systemroot%\*. /mp /s
    c:\$recycle.bin\*.* /s
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    nvstor32.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    explorer.exe
    svchost.exe
    userinit.exe
    qmgr.dll
    ws2_32.dll
    proquota.exe
    imm32.dll
    kernel32.dll
    ndis.sys
    autochk.exe
    spoolsv.exe
    xmlprov.dll
    ntmssvc.dll
    mswsock.dll
    Beep.SYS
    ntfs.sys
    termsrv.dll
    sfcfiles.dll
    st3shark.sys
    ahcix86.sys
    srsvc.dll
    nvrd32.sys
    /md5stop
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %SYSTEMDRIVE%\*.*
    %userprofile%\Desktop\*.*
    %userprofile%\Desktop\*.

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Please download GMER from one of the following locations and save it to your desktop:

  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.

  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.
    gmer_zip.gif
  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system...click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save... button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and re-enable all active protection when done.

-- If you encounter any problems, try running GMER in Safe Mode.

Link to post
Share on other sites

Hi Chamber. Thanks for the response.

Since no one was able to reply until now I had to take alternative action to try to save my computer. I was quickly losing control and the virus was taking over.

As a last resort I had a representative from Dell dial into my computer and clean off the rootkit.agent. It took him over an hour using a combination of DOS commands and a wide variety of programs (Prevx CSI, Trojan Remover, etc), but he was able to clean everything up and I have been virus free for the past 3 days. Malwarebytes, a-squared, AVG, and those other programs I just mentioned are all coming up completely clean now - finally.

It cost me $100 BUT WAS COMPLETELY WORTH IT and saved my HOURS AND HOURS AND HOURS of work trying or reformating.

The Geek Squad at Best Buy also can dial into your computer and do this as well. TOTALLY WORTH IT, at least so far.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.