Win32/Mebroot.k Trojan

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Hummel, Jul 27, 2008.

  1. Hummel

    Hummel Private E-2

    Hi,

    I'm new here and my PC seems to be infected with the Win32/Mebroot.k trojan. This morning I booted and got the following message from NOD32:

    Wi32/Mebroot.k Trojan - Master Boot Record Physical Disk 2

    I use Windows XP with Service Pack 3 and the Firewall is activated. NOD32 cannot remove or repair this problem.

    Also, I have read the threads here and googled, but have found no adequate solution.

    I followed the cleaning routine posted in your sticky. Unfortunately it did not help.

    I have not noticed any problems caused by the trojan, but it is quite unsetteling just knowing that it is present.

    Thanks for your help!

    Hummel
     

    Attached Files:

  2. Hummel

    Hummel Private E-2

    Here is the 4th attachment.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You did not attach the logs from SUPERAntispyware. You attach the instructions for running it that you must have saved to a text file. SAS will not fix this problem anyway none of the cleaning procedures will fix a master boot record problem.

    Try running this Using Dr.Web CureIt and attach the requested log afterwards. Then reboot. Then see if NOD32 still detects the problem.
     
  4. Hummel

    Hummel Private E-2

    Hi Chaslang,

    sorry for post a wrong file! I took your advice and ran CUREIT. It found a few things (10) which I all moved into quarantain. After rebooting and running NOD32, its not finding anything anymore. Does this mean my computer is now clean or ist the "infection simply hiding"??? I am attaching the log file. Thanks again for helping so quickly.

    Hummel
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If NOD32 is not finding the same problem anymore then it would appear you MBR has been fixed.


    Now we need to cleanup some items from running ComboFix.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the combo-fix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combo-fix folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  6. Hummel

    Hummel Private E-2

    Hi Chaslang,

    I just performed the fixme.reg thing. It worked perfectly. Thanks again. I will now follow and complete the further steps that you posted.

    Thank you
    Hummel
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds