I've got a Windows Server 2003 with some kind of malware. I've gotten rid of most of it, but there is one bug that I just can't get rid of. The main problem is a lot of the tools to get rid of these pesky bugs don't work on server OS.
All windows updates have been applied. There are no Antivirus or antimalware programs running at the moment. Just Malwarebytes installed.
I have followed the guide.
The DDS log says this OS is not supported.
Here is the Gmer log....
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2011-01-19 23:14:08
Windows 5.2.3790 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 Intel___ rev.0.1.
Running: 7cr2mei4.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1\fwtdrpow.sys
---- Kernel code sections - GMER 1.0.15 ----
? ACPI.sys The system cannot find the file specified. !
? pci.sys The system cannot find the file specified. !
? isapnp.sys The system cannot find the file specified. !
? pciide.sys The system cannot find the file specified. !
? intelide.sys The system cannot find the file specified. !
? MountMgr.sys The system cannot find the file specified. !
? ftdisk.sys The system cannot find the file specified. !
? dmload.sys The system cannot find the file specified. !
? dmio.sys The system cannot find the file specified. !
? volsnap.sys The system cannot find the file specified. !
? PartMgr.sys The system cannot find the file specified. !
? atapi.sys The system cannot find the file specified. !
? iaStor.sys The system cannot find the file specified. !
? disk.sys The system cannot find the file specified. !
? fltmgr.sys The system cannot find the file specified. !
? Dfs.sys The system cannot find the file specified. !
? KSecDD.sys The system cannot find the file specified. !
? Ntfs.sys The system cannot find the file specified. !
? NDIS.sys The system cannot find the file specified. !
? Mup.sys The system cannot find the file specified. !
? crcdisk.sys The system cannot find the file specified. !
? agp440.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
UPX1 C:\WINDOWS\TEMP\csrss.exe[2260] C:\WINDOWS\TEMP\csrss.exe entry point in "UPX1" section [0x004BEF20]
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys
AttachedDevice \FileSystem\Fastfat \Fat Dfs.sys
---- EOF - GMER 1.0.15 ----
The problem file is of course c:\windows\temp\csrss.exe. The real csrss.exe in the Windows\system32 folder seems fine and is only 4K in size I think. Its this one in the temp folder that Malwarebytes and other programs just can't get rid of. When I boot into safe mode the file doesn't exist and Malwarebytes doesn't find anything wrong. If I do an online scan of this file no antivirus thinks its bad.
Any ideas would be great!
Thanks,
Konrad