![]() |
Deleting the undeletable and more |
Post Reply
|
Page 123> |
| Author | ||
peral00
Newbie
Joined: 23 April 2007 Location: Italy Online Status: Offline Posts: 14 |
Quote Reply
Topic: Deleting the undeletable and morePosted: 23 April 2007 at 6:19pm |
|
|
To start I feel I should appologize for showing up in this forum as I am the victim of my own forgetfulness. I was working on my computer off-line and had shut off my firewall and antivirus... and forgot about it. After a week or more of surfing unprotected here I sit, writing you, hoping for some help getting rid of some malware.
When I got everything turned on my AVG lit up. I proceeded to clean out several trojan hores (various forms of generic3, generic2, dialer.dam and dialer.28.F). There was and still is one that I can't get rid of. No matter what I do I can't seem to access it. I've renaimed it and the warning does't pop up any more but it is still there. I've tried movefile, CCleaner, working from safemode, and dos (changing the attributes). It's residing in the system32 folder. It was Kodaksync.exe but I renamed it to Kodakthreat.txt which seemed to satisfy AVG Resident Shield (it never showed up in the anti-virus scans though it is listed as unopenable it the Nod32 scans - but not as a virus).
There is/was another C:\:teQxp.exe (Trojan horse Generic.XDJ) that I couldn't see with any program (also set off the Resident Shield alarm only) that I may have taken care of with movefile "" but I can't be sure since I've never been able to see it. I'm open to suggestions you have for getting rid of and double checking that it has been deleated.
Since I was pretty sure that I wouldn't get off so easily I've run AVG anti-rootkit and Rootkitreveal, taken snapshotes with autorun and hijackthis, and tried looking at the system with program explorer. Unfortunately my ability to interpret what I've been looking at is extremely limited but it does seem that there are some odd files still living quite happily in their little nooks and crannies. Again, any suggestions for next steps are most welcome.
Thank you Edited by peral00 - 27 April 2007 at 2:42am |
||
![]() |
||
Karlchen
Senior Member
Joined: 18 June 2005 Location: Germany Online Status: Offline Posts: 5121 |
Quote Reply
Posted: 24 April 2007 at 2:54am |
|
|
Good morning, peral00.
E.g. this thread, movefile , mentions at minimum 3 products capable of removing cloaked processes and executable files. HTH, Karl |
||
![]() |
||
peral00
Newbie
Joined: 23 April 2007 Location: Italy Online Status: Offline Posts: 14 |
Quote Reply
Posted: 24 April 2007 at 4:13am |
|
|
Sorry for the repeat, I will give them a try. I think I reached to point of saying HELP!
I have to admit I'm a bit overwhelmed by a) the number of viruses I've read about but more importantantly b) by the number of tools out there that. Is there a catagorized listing of anti-malware tools out there in cyberspace? Like many other newbies to the anti-malware world who end up posting, I've already followed the advice I've seen in other posts from various forums, used I think 17 or 18 different tools (AV, rootkit, removal tools, monitoring tools, etc), run many of the tools multiple times, still have an infection that I know about, and there one or two other files that I can't confirm if they are a problem or not.
I will finish this by saying that I do GREATLY appreciate you're (in the royal sense) willingness to read these threads from people like myself who are struggling with the unknown and to provide useful advice. So... thanks.
Peral00
|
||
![]() |
||
peral00
Newbie
Joined: 23 April 2007 Location: Italy Online Status: Offline Posts: 14 |
Quote Reply
Posted: 24 April 2007 at 11:17am |
|
|
fyi - Rootkit Unhooker was unable to do the job but Ice Sword did quite it quite nicely. Ice Sword also indicated that the :teQxp.exe file is an Intel file used to monitor the PROset wi-fi system. Didn't find anything on this file by Googling nor on the Intel website. I've written them to ask about it. Now on to determin if I've got some other invaders. Thanks again for your help. Peral00 |
||
![]() |
||
Karlchen
Senior Member
Joined: 18 June 2005 Location: Germany Online Status: Offline Posts: 5121 |
Quote Reply
Posted: 24 April 2007 at 4:41pm |
|
|
Good evening, peral00.
Good to learn that one of the suggested ARK tools proved to be helpful in your case.
Just a short note on your previous message: Yep, I can understand that you - like any other computer user who has not devoted his life to malware hunting completely - will be in a plight: The anti-malware programmes that are easy to handle often perform pretty poorly on their main task: finding and eliminating malware. The anti-malware programmes that catch malware more reliably often are difficult to handle. Hopefully in the end you will succeed and get rid of any malicious beast in your system.
Ciao, Karl |
||
![]() |
||
lucass
Newbie
Joined: 07 December 2006 Location: Italy Online Status: Offline Posts: 11 |
Quote Reply
Posted: 24 April 2007 at 6:46pm |
|
Hi, the file C:\:teQxp.exe is a ads(alternative data streams) Your pc is infected with gromozon(aka linkoptmizer) rootkit. Removal from prevx http://www.prevx.com/gromozon.asp Removal tool from Symantec http://www.symantec.com/smb/security_response/writeup.jsp?docid=2006-092316-4153-99 Cheers ![]() |
||
![]() |
||
peral00
Newbie
Joined: 23 April 2007 Location: Italy Online Status: Offline Posts: 14 |
Quote Reply
Posted: 25 April 2007 at 3:18am |
|
|
Thanks for the moral support Karl. After days of working on this it comes in useful.
Good catch lucass, grazie e buon 25 aprile.
You've just confirmed what I also just learned from EP_XOFF in the Rootkit Revealer log thread except there the culprit showed up as c:\windows\system32\com6.eaz.
Because certain level of redundancy seems to be called for in these matters I'll repeat what I said in the other post.... I'm off to try and kill the beast. If I don't return by tomorrow please call my mom.
Peral00 Edited by peral00 - 25 April 2007 at 3:22am |
||
![]() |
||
lucass
Newbie
Joined: 07 December 2006 Location: Italy Online Status: Offline Posts: 11 |
Quote Reply
Posted: 25 April 2007 at 5:31am |
|
Thanks You're welcome ![]() Ciao |
||
![]() |
||
peral00
Newbie
Joined: 23 April 2007 Location: Italy Online Status: Offline Posts: 14 |
Quote Reply
Posted: 25 April 2007 at 6:34am |
|
|
Update, I ran the Symantec tool and according to Unhooker and Rootkit Revealer the com6.eaz problem seems to be taken care of but C:/:teQxp.exe is still there according to Ice Sword.
Intel wrote back and said it isn't their file. It seems I mis-read the description in the Win32 Services, it actually states the the file
"Manages the event trace messages for all the components of Intel(R) PROset/Wireless software" I've come to the realization that it isn't clear to me from Lucass' post if the file was utilized/infected by gromozon or was actually added by the rootkit and needs to be eliminated. Thoughts? An aside, if I need to delete it I'm not sure how to since the only place it shows up in Ice Sword I only have the choice to stop, run the process automatically, manually, or disable - I've disabled it for the time being.
Peral00
|
||
![]() |
||
lucass
Newbie
Joined: 07 December 2006 Location: Italy Online Status: Offline Posts: 11 |
Quote Reply
Posted: 25 April 2007 at 2:35pm |
|
|
Yes, is a gromozon rookit
The malware used a reserved name, ads, efs and other tricks Regards PS:manual remover http://www.suspectfile.com/forum/viewtopic.php?t=156 Edited by lucass - 25 April 2007 at 2:40pm |
||
![]() |
||
Post Reply
|
Page 123> |
| Forum Jump | Forum Permissions ![]() You cannot post new topics in this forum You cannot reply to topics in this forum You cannot delete your posts in this forum You cannot edit your posts in this forum You cannot create polls in this forum You cannot vote in polls in this forum |