CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

[DONE]kdaiz.exe - rootkit?

 
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
bongobill

Guest
IP: 80.41.*.*






PostPosted: Sat Aug 25, 2007 4:21 pm    Post subject: kdaiz.exe - rootkit?
Reply with quote

A buddy has used AVG rootkit remover and found the file:

C:\WINDOWS\system32\kdaiz.exe

It's classed as a 'Hidden File' - Google doesn't find an explanation of this file anywhere.

Anyone got any ideas?

bb

Back to top
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Sat Aug 25, 2007 8:03 pm    Post subject:
Reply with quote

Please upload the file to our Unknown Files forum for analysis. Our Unknown Files forum is here:

CastleCops Link/f81-Unknown_Files.html

Follow the instructions here:

CastleCops Link/t27288-FAQ_on_Unknown_or_Malware_Files.html

Post the file(s) as an attachment to a new topic, and include a link to this topic in your post. Then post a link here for me to follow the analysis of the file(s).


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
swatkat

Security Expert


Joined: Mar 04, 2005
Posts: 2039

MVP RootKit Detection Hosts Rootkit Experts Security Experts

PostPosted: Mon Aug 27, 2007 4:07 am    Post subject:
Reply with quote

Hi,
It could be related to Zlob fake codec rootkit. To verify this, go to Start Menu > Run. Here, type regedit and press Enter key. In the Registry Editor, navigate to the following key (by clicking the "+" symbols):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Click on the above-mentioned Winlogon key to select it. Now, in the right-side pane of Registry Editor, there should be a value called System under the "Name" column. Please check what is there in "Data" column corresponding to this System value.
If you see kdaiz.exe in front of System value, then it's Zlob rootkit. Then, it's better to remove it using AVG Anti-Rootkit or any other anti-rootkit tools.


_________________
Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.
- Albert Einstein
Back to top
View users profile Send private message Visit posters website
bongobill

Guest
IP: 86.129.*.*






PostPosted: Mon Aug 27, 2007 4:21 pm    Post subject: Kdaiz.exe upload to Unknown Files forum - extension error
Reply with quote

Hi,

Sorry, but can't upload the suspect file because AVG Anti-Rootkit won't allow the saving of the file in a form the Unknown Files forum will accept.

Thanks to swatkat for your advice - appreciated - the file is as you describe. Will attempt removal.

Regards,

BB

Back to top
bongobill

Guest
IP: 86.129.*.*






PostPosted: Mon Aug 27, 2007 4:54 pm    Post subject: AVG Anti-Rootkit removal failed
Reply with quote

Hi,

AVG Anti-Rootkit reports that the rootkit has been deleted, but on re-scanning, it still finds the file kdaiz.exe exactly wher eit was before. I have performed this operation on the infected computer a couple of ties and a scan still finds the file.

Any help appeciated,

BB

Back to top
bongobill

Guest
IP: 86.129.*.*






PostPosted: Mon Aug 27, 2007 5:31 pm    Post subject: McAfee Rootkit remover renamed fille
Reply with quote

Hi again,

I've downloaded McAfee Rootkit Remover and it detected kdaiz.exe. I've sent a copy to McAfee and have renamed the file. Both McAfee and AVG rootkit removers now do not detect the file. Hopefully the problem is solved. It's been a persistent little devil!

Regards,

BB

Back to top
swatkat

Security Expert


Joined: Mar 04, 2005
Posts: 2039

MVP RootKit Detection Hosts Rootkit Experts Security Experts

PostPosted: Tue Aug 28, 2007 5:17 pm    Post subject:
Reply with quote

Hi,
Glad to hear that you were able to remove the rootkit Smile To prevent such infections in future, you can take a look at CastleCops Malware Re-Infection Prevention page here:
http://wiki.castlecops.com/Malware_Prevention:_Prevent_Re-infection


_________________
Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.
- Albert Einstein
Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer