Avast WEBforum

Other => Viruses and worms => Topic started by: enovak on October 26, 2012, 11:54:40 PM

Title: Avast reports rookit:hidden file on scan, but can't remove/repair/move file
Post by: enovak on October 26, 2012, 11:54:40 PM
Ran a scan today and Avast found Threat: Rootkit: hidden file, plus four other files that indicated Error: Data error (cyclic redundancy check) (23)

The rootkit is associated with:

C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Cach#\0c4ec58f70e0fe6e74458c35fb260e2d\Syste.Runtime.Caching.ni.dll

The 4 files that indicated the CRC error were:

C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Cach#
C:\WINDOWS\Temp\FLT1985.tmp
C:\WINDOWS\Temp\FLT1986.tmp

A boot scan did not yield any problems.

A subsequent Full System scan yielded the same result as above.

I cannot move the file to the chest, repair it, or remove it.

What are my next steps to remove this?  Is it a legitimate threat?

Thank you!
Title: Re: Avast reports rookit:hidden file on scan, but can't remove/repair/move file
Post by: essexboy on October 27, 2012, 12:25:12 PM
A CRC error means that the file is corrupt
Title: Re: Avast reports rookit:hidden file on scan, but can't remove/repair/move file
Post by: enovak on October 27, 2012, 03:42:59 PM
Am I actually infected with a rootkit?  Or is the file simply corrupted?

Also is there a way to resolve this?

Thank you in advance for all your help!
Title: Re: Avast reports rookit:hidden file on scan, but can't remove/repair/move file
Post by: essexboy on October 27, 2012, 03:59:39 PM
The only way to determine that is to run a scan

Download aswMBR.exe (http://public.avast.com/~gmerek/aswMBR.exe) ( 4.5mb ) to your desktop.
 Double click the aswMBR.exe to run it  Click the "Scan" button to start scan 

(http://i1224.photobucket.com/albums/ee362/Essexboy3/aswMBR%20shots/aswMBRScan.gif)


On completion of the scan click save log, save it to your desktop and post in your next reply
Title: Re: Avast reports rookit:hidden file on scan, but can't remove/repair/move file
Post by: enovak on October 27, 2012, 06:20:58 PM
Running scan now.   It flagged that same file.  I will post the complete scan when it finishes.

Thank you
Title: Re: Avast reports rookit:hidden file on scan, but can't remove/repair/move file
Post by: enovak on October 27, 2012, 06:27:00 PM
Attached is the log from the aswMBR scan.
Title: Re: Avast reports rookit:hidden file on scan, but can't remove/repair/move file
Post by: essexboy on October 27, 2012, 07:37:28 PM
How is the computer behaving, any problems ?
Title: Re: Avast reports rookit:hidden file on scan, but can't remove/repair/move file
Post by: enovak on October 27, 2012, 07:58:04 PM
No errors or strange behavior, just sometimes there is a lot of disk activity that I can't account for which slows the system down.  In some cases I see AppleMobileDeviceServices chewing up 50% of my CPU - I kill that process and that resolves that.  I believe it is a known problem with Apple?

Also sometime the WLTRAY.EXE process seems to have a memory leak and consumes more and more memory.  A reboot resolves that.

No strange behavior on reboot.

I also ran an ESET online scan on the laptop, but it only found two undesirable apps that I may not want - and those were recent installs that I have since removed.

Has aswMBR actually removed/resolved/repaired  the file in question?
Title: Re: Avast reports rookit:hidden file on scan, but can't remove/repair/move file
Post by: essexboy on October 27, 2012, 08:15:25 PM
No it just noted that it was hidden, that in itself is not a problem..  As some windows files are hidden
Title: Re: Avast reports rookit:hidden file on scan, but can't remove/repair/move file
Post by: enovak on October 27, 2012, 08:24:11 PM
Any thoughts on how to clear this with regard to the scan?  This has never shown up before.   And boot scan does not indicate anything.  I am running another ESET scan currently and will let you know if it yields anything.

Just concerned that there is something lurking...
Title: Re: Avast reports rookit:hidden file on scan, but can't remove/repair/move file
Post by: essexboy on October 27, 2012, 08:36:21 PM
If you are concerned I could delete the file, but a programme that uses dotnet may not function properly
Title: Re: Avast reports rookit:hidden file on scan, but can't remove/repair/move file
Post by: enovak on October 27, 2012, 08:59:32 PM
Can I remove support for .Net and then restore/install support for .Net?  Do you think that would resolve it?  Since Avast keeps finding the CRC errors on those files?
Title: Re: Avast reports rookit:hidden file on scan, but can't remove/repair/move file
Post by: essexboy on October 27, 2012, 09:42:05 PM
With the CRC errors it may be prudent to remove all dotnet versions and install just the ones you need

Download the dotnet cleanup tool from here http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Components-PostAttachments/00-08-90-44-93/dotnetfx_5F00_cleanup_5F00_tool.zip to your desktop
Extract Cleanup_tool.exe to the desktop and run

Then re-run aswMBR
Title: Re: Avast reports rookit:hidden file on scan, but can't remove/repair/move file
Post by: enovak on October 28, 2012, 05:52:53 AM
Ran the cleanup tool and removed all versions of .Net - but aswMBR reports the same thing.

See attached log
Title: Re: Avast reports rookit:hidden file on scan, but can't remove/repair/move file
Post by: essexboy on October 28, 2012, 12:40:59 PM
OK I shall now kill it for you

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
Code: [Select]
:Files
C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Cach#\0c4ec58f70e0fe6e74458c35fb260e2d\System.Runtime.Caching.ni.dll

:Commands
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]
Title: Re: Avast reports rookit:hidden file on scan, but can't remove/repair/move file
Post by: enovak on October 28, 2012, 01:38:31 PM
Here is the log result that popped up upon reboot.

I have not re-run OTL yet.  Please let me know if I need to re-run OTL in scan mode, and whether I need to paste the same information in the scan files area before the scan.
Title: Re: Avast reports rookit:hidden file on scan, but can't remove/repair/move file
Post by: essexboy on October 28, 2012, 01:55:10 PM
According to OTL that file is not on your system

Lets see if there is an additional copy, or if it is created by the net framework as required

(https://dl.dropbox.com/u/73555776/OTL_Main_Tutorial.gif)

netsvcs
/md5start
System.Runtime.Caching.ni.dll
/md5stop
CREATERESTOREPOINT


Title: Re: Avast reports rookit:hidden file on scan, but can't remove/repair/move file
Post by: enovak on October 28, 2012, 03:17:53 PM
Here are the results of the scan - and thank you again for all your help!
Title: Re: Avast reports rookit:hidden file on scan, but can't remove/repair/move file
Post by: enovak on October 28, 2012, 03:19:52 PM
Just in case the previous logs were the ones from the wrong run, here are the correct ones:
Title: Re: Avast reports rookit:hidden file on scan, but can't remove/repair/move file
Post by: essexboy on October 28, 2012, 04:04:25 PM
Still can't find it... Lets go fishing

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1  (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here  (http://forums.whatthetech.com/How_Disable_your_Security_Programs_t96260.html&pid=494216#entry494216)
(http://img.photobucket.com/albums/v706/ried7/NSIS_disclaimer_ENG.png)

(http://img.photobucket.com/albums/v706/ried7/NSIS_extraction.png)

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Title: Re: Avast reports rookit:hidden file on scan, but can't remove/repair/move file
Post by: enovak on October 28, 2012, 04:55:37 PM
Here is the resulting log from CombFix.  I am not sure the system rebooted as I was not at the console when it ran to completion.
Title: Re: Avast reports rookit:hidden file on scan, but can't remove/repair/move file
Post by: enovak on October 28, 2012, 04:57:26 PM
And here is the C:\ComboFix.txt file you requested.
Title: Re: Avast reports rookit:hidden file on scan, but can't remove/repair/move file
Post by: essexboy on October 28, 2012, 05:23:54 PM
Not even combofix/GMER is finding a hidden file there...  I wonder if it is associated with SAS as I believe that uses the net framework
Title: Re: Avast reports rookit:hidden file on scan, but can't remove/repair/move file
Post by: enovak on October 28, 2012, 07:03:28 PM
I don't know what SAS is.   Should I try re-installing .Net framework to see if it will over-write the file?
Title: Re: Avast reports rookit:hidden file on scan, but can't remove/repair/move file
Post by: enovak on October 28, 2012, 07:09:57 PM
Is SAS Super Anti-Spyware app?  I do have that installed - or at least I did at one time.
Title: Re: Avast reports rookit:hidden file on scan, but can't remove/repair/move file
Post by: DavidR on October 28, 2012, 07:22:55 PM
Is SAS Super Anti-Spyware app?  I do have that installed - or at least I did at one time.

Yes SAS is Super AntiSpyware.

I have SAS Pro, but resident protection is disabled (as I also have MBAM) and I haven't come across anything like this. I have a whole slew of different .net framework versions.
Title: Re: Avast reports rookit:hidden file on scan, but can't remove/repair/move file
Post by: essexboy on October 28, 2012, 09:06:50 PM
Yes try a re-install