Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old May 17th, 2010, 10:39 AM
kensaundm31 kensaundm31 is offline
Infrequent Poster
 
Join Date: May 2010
Posts: 17
Default ukkeegz.sys

Hi,

Malware keeps identifying c:\windows\system32\drivers\ukkeegz.sys as a rootkit agent.

But I remember seeing it loading when you boot xp in logging mode so I think it is a valid system file.

I added it to the ignore list.

I just want to check that I am right. Am I?
  #2  
Old May 17th, 2010, 11:04 AM
raven211's Avatar
raven211 raven211 is offline
Very Frequent Poster
 
Join Date: May 2005
Posts: 2,552
Default Re: ukkeegz.sys

Quote:
Originally Posted by kensaundm31
Hi,

Malware keeps identifying c:\windows\system32\drivers\ukkeegz.sys as a rootkit agent.

But I remember seeing it loading when you boot xp in logging mode so I think it is a valid system file.

I added it to the ignore list.

I just want to check that I am right. Am I?


Of course it's loading on boot-up - that's the point of malwares' running, isn't it? You're infected, just get rid of it.


What detected this file? I suppose it's just a piece of a malware since there are no results on Google, only this post on Wilders.
  #3  
Old May 17th, 2010, 11:14 AM
HAN's Avatar
HAN HAN is offline
Very Frequent Poster
 
Join Date: Feb 2005
Location: USA
Posts: 1,718
Default Re: ukkeegz.sys

IMO, raven211 is right. I believe you are infected and that is not a good file.
  #4  
Old May 17th, 2010, 11:42 AM
SweX SweX is online now
Massive Poster
 
Join Date: Apr 2007
Location: Sweden
Posts: 3,639
Default Re: ukkeegz.sys

Upload it to Virustotal.com and see if any other vendor than yours
detects it, if some others do then it's highly likely malware unfortunately.
__________________
OpenDNS ESET Smart Security
-A Heavy product is not the same as a Bloated product and vice versa-
  #5  
Old May 17th, 2010, 02:41 PM
blacknight's Avatar
blacknight blacknight is offline
Very Frequent Poster
 
Join Date: Sep 2007
Location: Europe
Posts: 1,596
Default Re: ukkeegz.sys

Quote:
Originally Posted by raven211

What detected this file? I suppose it's just a piece of a malware since there are no results on Google, only this post on Wilders.


The same found I. I have not it in my system32\drivers; not a bad idea a scan with RootRepeal or GMER or similar real anti rootkits.
  #6  
Old May 17th, 2010, 02:55 PM
Cudni's Avatar
Cudni Cudni is offline
Global Moderator
 
Join Date: May 2009
Location: Somethingshire
Posts: 6,944
Default Re: ukkeegz.sys

that sounds very much like malware. use help from dedicated volunteer sites listed
http://www.wilderssecurity.com/showp...81&postcount=3
__________________
once we only had ideals, today they are the only things we are missing
Microsoft MVP, 2006 - 2013/14
  #7  
Old May 17th, 2010, 03:47 PM
raven211's Avatar
raven211 raven211 is offline
Very Frequent Poster
 
Join Date: May 2005
Posts: 2,552
Default Re: ukkeegz.sys

When my friend had this kind of associated file I asked him to use Hitman Pro and Malwarebytes'. After that he didn't seem to have problems (that were malware related ).
  #8  
Old May 17th, 2010, 06:23 PM
kensaundm31 kensaundm31 is offline
Infrequent Poster
 
Join Date: May 2010
Posts: 17
Default Re: ukkeegz.sys

Wow, thats scary, i honestly thought it was an xp file!

I tried to upload it to that site but it would not allow itself to be imported/attached to an email.

It also would not accept being zipped.

So get rid and stay rid then...

Thanks for the help.
  #9  
Old May 17th, 2010, 06:51 PM
kensaundm31 kensaundm31 is offline
Infrequent Poster
 
Join Date: May 2010
Posts: 17
Default Re: ukkeegz.sys

I cant get rid of it!!!!!

Malware bytes says it will delete it on reboot.

But as soon as i look it is back there. I do believe malwarebytes is deleting it because the date and time of the file is the same as when i just booted.

So how is it re-establishing itself? What do i do?
  #10  
Old May 17th, 2010, 06:55 PM
doktornotor's Avatar
doktornotor doktornotor is offline
Very Frequent Poster
 
Join Date: Jul 2008
Posts: 2,045
Default Re: ukkeegz.sys

Quote:
Originally Posted by kensaundm31
So how is it re-establishing itself? What do i do?

Help: I Got Hacked. Now What Do I Do?

IOW: rootkit -> game over.
  #11  
Old May 17th, 2010, 07:03 PM
Victek123's Avatar
Victek123 Victek123 is offline
Very Frequent Poster
 
Join Date: Nov 2007
Location: USA
Posts: 2,719
Default Re: ukkeegz.sys

Quote:
Originally Posted by kensaundm31
I cant get rid of it!!!!!

Malware bytes says it will delete it on reboot.

But as soon as i look it is back there. I do believe malwarebytes is deleting it because the date and time of the file is the same as when i just booted.

So how is it re-establishing itself? What do i do?
.
Try SuperAntiSpyware - it makes a point of targeting rootkits. You could also try creating a log with "HiJackThis" and uploading it to a tech forum for analysis. Sorry, I can't immediately recommend a forum but there are a number of them. I'm sure someone here can suggest one.
__________________
ut quod ego verus est maioribus quam ut quod est sanctus
  #12  
Old May 17th, 2010, 07:16 PM
kjdemuth's Avatar
kjdemuth kjdemuth is offline
Very Frequent Poster
 
Join Date: Jul 2005
Location: Boston, MA
Posts: 2,340
Default Re: ukkeegz.sys

Emsisoft has a good group of folks. Go over to the support section. They have a malware removal section. Excellent, step by step help. You can also try running hijackthis and going over to http://hjt-data.trendmicro.com/hjt/a...this/index.php.
__________________
Realtime:
WSA AV (Maxed Settings), Sandboxie Paid ( Dropmyrights and Browsers sandboxed) Lifetime license, NVT EXE Radar Pro (Lockdown mode). K9 Web protection. (malware, phishing and HTTPS force) Norton DNS.
On-Demand:
MBAM+EAM
Hitman pro (Scans daily)
  #13  
Old May 17th, 2010, 07:17 PM
ace55 ace55 is offline
Regular Poster
 
Join Date: Mar 2010
Posts: 91
Default Re: ukkeegz.sys

Reformat and reinstall. You shouldn't trust a system after discovering it is compromised, as you can never be sure you have fully removed all infections.

That said, burn a live CD on a separate computer. You can boot to it, use it to upload the file to virustotal, look around your machine and see what else you can find that is presumably hidden by this driver.
  #14  
Old May 17th, 2010, 07:23 PM
Buster_BSA Buster_BSA is offline
Frequent Poster
 
Join Date: Nov 2009
Posts: 545
Default Re: ukkeegz.sys

Give DrWeb Cureit! an opportunity to clean the critter.
  #15  
Old May 17th, 2010, 07:31 PM
Konata Izumi's Avatar
Konata Izumi Konata Izumi is offline
Very Frequent Poster
 
Join Date: Nov 2008
Posts: 1,512
Default Re: ukkeegz.sys

Quote:
Originally Posted by ace55
Reformat and reinstall. You shouldn't trust a system after discovering it is compromised, as you can never be sure you have fully removed all infections.

That said, burn a live CD on a separate computer. You can boot to it, use it to upload the file to virustotal, look around your machine and see what else you can find that is presumably hidden by this driver.

This. I agree.
__________________
Win7PRO64bit | SUA | SRP | UAC | EMET | SpywareBlaster | MVPSHOST | OpenDNS | SandboxIE | Privoxy | Windows Image Backup .
built-in security + sandboxing fag.
  #16  
Old May 17th, 2010, 09:02 PM
kensaundm31 kensaundm31 is offline
Infrequent Poster
 
Join Date: May 2010
Posts: 17
Default Re: ukkeegz.sys

Well, I decided to boot from my other operating system as I have a dual-boot setup.

I did this to see if i could copy or zip the file to send for analysis, because it wouldn't let me on the affected os.

I did that but then I deleted it as well.

I just booted again and it has stayed deleted...

So I guess I'll send it for analysis.

ESET has identified the moved ukkeegz.sys file as 'Win32/Bubnix.A'

from another post:
Steve123
Member Join Date: Feb 2008
Posts: 2,216

Boot Bus Extender rootkit dwonloaded by Win32/Bubnix.A. trojan downloader

--------------------------------------------------------------------------------

This trojan will attempt to connect to the internet to download the VirTool: Win32/Rootkit.BV, which is a trojan rootkit. It will download the trojan rootkit at <system folder>\driver\<random>.sys location. To safeguard the rootkit from been deleted by the anti virus the rootkit is registered with the kernel driver service and named Boot Bus Extender.


Whilst looking through the logs from some of the rootkit scanners i noticed 'boot bus extender'.

Any way I sent the file to scan@virustotal.com




Thanks for the help.

Last edited by kensaundm31 : May 17th, 2010 at 09:24 PM.
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:55 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums