Possible MBR rootkit on Win2K server

Hi all,

A few days ago I received a message from a client I do part-time system admin work for, showing a bounce message for an email they sent referring to reputation problems (they had been blacklisted). A number of scans were performed on the server, including a DrWeb CureIt scan from a PE bootdisk, which turned up nothing. HijackThis and RunScanner logs looked pretty clean to me. I'm fairly experienced in removing the more stubborn infections with these tools and have had a great deal of success with them. Many of the anti-rootkit tools like Rootrepeal failed with a message that they can't load the driver, find a handle to the driver, or that an "overlapped I/O operation is in progress". GMER fails with the overlapped I/O error: code 0xC000010E. Suspicious. Attempts to run Process Explorer under AntiHookExec failed.

This system runs Exchange and ASSP for email spam and virus filtering and the only true confirmation that there was malware running on the machine was a network traffic capture with WireShark showing all kinds of SMTP traffic being sent even though Exchange had been shut down. Email addresses to be spammed were coming in on port 1080 (SOCKS), and the spam traffic was going out on 25. There was also HTTP traffic present and coming through the SOCKS port, making it appear that the server may have been turned into an anonymous web proxy as well. I'd have to take a more in-depth look at that capture to be sure.

Using a number of tools including IceSword and "UnHackMe", I was able to remove the hidden malware processes on the system and the server is no longer sending out spam. One of the processes was named rtrpl.sys but most of them were randomly named and would keep reappearing after a reboot until it seemed that I got them all. MBAM found a single rogue.virex or it may have been rogue.unvirex process and removed it.

A differential scan of the machine to compare directory listings from the native OS and a PE boot yielded no significant differences and an "offline" (PE boot) dump of the registry, looking in the usual suspect areas of hkxx>...>run, etc yielded no additional entries.

I still can't run many of the rootkit tools and GMER's mbr.exe gives me:

device: opened successfully

user: MBR read successfully

kernel: error reading MBR

Trying to use mbr.exe to copy the boot sector to a file gives the error:

error: Read The handle is invalid.

It's possible that the UnHackMe/Partizan driver could be causing some of these issues.

I'm currently offsite so I can't do on offline fixmbr but am thinking that might be a good idea at this point. I'd like to be sure that everything is gone.

I can't send you the ark file from GMER since GMER fails with the error message given above. The interface still comes up but I doubt it will be of much use since the driver apparently won't load.

Any help or advice would be greatly appreciated, I think I may have finally met my match.

Thanks and best regards,

- Phil



Hi and welcome to Malwarebytes.

My apologies for the extended delay. Do you still need help?

Hi screen317,

Thanks for replying.

I think I got it all... rewriting the MBR seemed to eliminate the last remnants... MBR.EXE can successfully read in both user and kernel mode now, and I no longer get the driver error with the rootkit tools.

Only one problem remains... I still cannot run RootRepeal. It displays the "Initializing" message, goes to near 100% utilization and grabs most of the available memory in the machine. Does RootRepeal have this problem with certain platforms/systems or should I be concerned about it? All other symptoms are gone.

- Phil

Hi Phil,

Good to hear you could figure it out.

Yes I imagine there are compatibility issues with some platforms, and there are a myriad of reasons for why rootkit scans fail (active SPTD drivers, etc.); let me know if there's anything else I can do for you.

Will do... thanks.

Glad we could help. :)

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

