Possible MBR Rootkit - logs attached #1

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jlapolla, Feb 27, 2010.

  1. jlapolla

    jlapolla Private E-2

    My daughter picked up an infection that had a ton of pop ups with Virus warnings, and redirects to porn pages. She ran Mbam, SAS, Spybot, Avast, from boot scans and Safe Mode, Mbam cleared some stuff, then it returned, then she brought the PC to me.
    I've worked through your process, trying my best to stick to all guidelines because I know they work.

    I got a notice that AVG was running, but I could not find it in the programs list, or anywhere else.

    I'm actually on the machine now, and it seems to be working OK.

    The only issue I can see is that the RR Report says an MBR Rootkit is detected.

    Logs are attached. I included TWO Mbam logs because today's was clean, but the one she ran yesterday shows some items removed.

    Please advise.

    Many thanks, and good luck with all the NJ snow.
    John
     

    Attached Files:

  2. jlapolla

    jlapolla Private E-2

    Possible MBR Rootkit - logs attached #2

    Conitinuation of post - last two logs attached.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please keep all your replies in this thread.


    Yes you do have a Master Boot Record (MBR) infection that needs to be removed which we will get to below. You will need to boot to the Recovery Console to remove this infection.

    Now boot to the Recovery Console and run the fixmbr to clear a Master Boot Record infection that you have.

    You can read the below to help you do this:

    http://support.microsoft.com/kb/307654


    Then boot back into normal mode.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
    Last edited: Feb 27, 2010
  4. jlapolla

    jlapolla Private E-2

    Hi Tim,

    Ran mbrfix - everthing seemed to go OK
    Ran Avenger and had an error message about tuornp not being a file. (it was an empty folder, which I now deleted)

    Everything seems to be OK, except the system seems a little slow, which may just be my imagination at this point.

    Files are attached. Please advise.

    Thanks very much for your help,
    John
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your newfiles log is empty. Let's have you do this>

    First:
    In the meantime, let's remove some junk.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The red is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    ShowNew <-- this will try to run another scan from MGtools. Tell me what error messages, if any, you see.

    If you get an error message, tell me what it is. Otherwise, attach the new MGLogs.zip.
     
  6. jlapolla

    jlapolla Private E-2

    Tim
    The HJT fixes worked fine.

    Your fixME.reg patch worked. Received a success message.

    Attached is a new log for MGtools.

    I had did some searches and found old AVG files/folders, even though AVG was not showing on the delete programs list. I have deleted all of these manually.

    In the process of trying to clean stuff up, I inadvertently deleted the MGtools folder, so to run this scan I did a freesh install. I hope that does not muck things up too much.

    thanks,
    John
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I need you to try what I posted again.
    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The red is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.

    Now tell me what errors you get.
     
  8. jlapolla

    jlapolla Private E-2

    Tim,
    Ran ShowNew from the cmd prompt. No errors,
    Updated MGlogs is attached.
    thanks,
    John
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Arrgghh!!!

    Click Start, Run, and enter cmd and click OK. This will open a command prompt Window. In the command prompt Window, enter the below commands each followed by the enter key:

    ver > c:\ver.txt
    dir C:\MGtools > C:\flist.txt

    Now attach the C:\ver.txt and C:\flist.txt files here. Note there is a space after the dir and before the >.
     
  10. jlapolla

    jlapolla Private E-2

    Sorry for the frustration.
    Both files are attached.
    thanks,
    John
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you disabled all your AV and AS software when you ran the Shownew.bat?
     
  12. jlapolla

    jlapolla Private E-2

    I am farily certain.
    Avast is stopped.
    MB anti malware, SAS, and Spybot are all passive. There is nothing else that I know of.
    What is the problem we are looking for?
    thanks,
    John
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The problem is that your newfiles log is empty. Please go to start / run / type:
    services.msc
    When that window opens, scroll down to the Windows Management Instrumentation (WMI) service and tell me what it is set to.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds