Browser redirects and fake security installs (possible rootkits)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by chupon, Nov 10, 2011.

  1. chupon

    chupon Private E-2

    Hi,

    I have an issue with a laptop of mine and I've tried some troubleshooting steps that have usually worked in the past, but this is proving a bit challenging. Things started when I noticed a fake anti-spyware program called System Restore which I promptly removed. While I was working to remove all traces another fake anti-spyware program called System Security 2012 popped up.

    At this point I thought there was something in the MBR so I've focused my efforts there but have so far been unlucky. I can't seem to run TDSS Killer even if I rename it. MalWare Bytes has removed items but isn't reporting anything right now, same with SAS.

    I am not confident to bring this laptop online as it seems fine when it's not connected to the internet but seems to display infection symptoms when connected.

    DDS doesn't want to end so I can't post a log. I get the following error wen I try to run GMER.

    "LoadDriver("C:\DOCUME~1\<user>\LOCALS~1\temp\fgloapod.sys") error 0xC000010E: Cannot create a stable subkey under a volatile parent key."

    As such I can't provide this log either.

    If I boot into SafeMode I sometimes get a blue screen and sometimes it works just fine. Same for a normal boot. It seems to happen more when I have my USB stick plugged in when I reboot so I've been removing that each time.

    If I try to boot to recovery mode it never seems to load. If I boot to a windows XP CD I can get to the repair option there but I haven't run anything yet.

    I was able to get MBRCheck to run.

    MBRCheck, version 1.2.3
    © 2010, AD

    Command-line:
    Windows Version: Windows XP Professional
    Windows Information: Service Pack 3 (build 2600)
    Logical Drives Mask: 0x000000ec

    \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`02738a00 (NTFS)

    Size Device Name MBR Status
    --------------------------------------------
    149 GB \\.\PhysicalDrive0 MBR Code Faked!
    SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A


    Found non-standard or infected MBR.

    I can't run ComboFix, it freezes when it gets to the step about the actual scan. I never see any lines about what stage it's on. I can tell it froze because the system clock does not update and the cursor does not blink in the console window anymore.

    I continued on and ran rootrepeal and mgtools.

    I really don't want to format at this point so I'm looking for options.

    Thanks.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have your XP install CD? If not, you can create a recovery console disc here:
    This is a download of an .iso file of just the Recovery Console for XP.
    Burn to CD with Nero or other 'disc image' capable tool and boot.

    XP Recovery Console.

    You can use ImageBurn to create the disc.

    Go into your bios and change the boot order to CD/DVD as first boot device. Insert the CD and reboot. Once in the Recovery Console type:
    fixmbr.

    I will look at your logs while you do this.

    Once you are done, Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...

    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Why did you run the scans in safe mode?

    Now download The Avenger by Swandog46 to your Desktop.

    See the download links under this icon [​IMG]
    Extract avenger.exe from the Zip file and save it to your desktop.

    1. Run avenger.exe by double-clicking on it.
    2. Click OK at the warning to continue to use The Avenger
    3. Do not change any of the check box options!
    4. Shut down your protection software now to avoid possible conflicts.
    5. Copy everything in the Quote box below, and paste it into the Input script here: part of The Avenger
    6. Now click the [​IMG] button
    7. Click Yes to the prompt to confirm you want to execute.
    8. Click Yes to the Reboot now? question that will appear when The Avenger finishes running.
    9. Your PC should reboot, if not, reboot it yourself.
    10. A log file from The Avenger will be produced at C:\avenger.txt and it will pop-up for you to view when you login after reboot.
    11. Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )


    Now boot into normal mode and run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  4. chupon

    chupon Private E-2

    I was having stability issues with some scans and running some in safe mode was proving better.

    Here are the logs you requested. I ran MBRCheck before and after the fixmbr and it gave the same output. The log is from afterwards.

    Edit: I guess I could say the system is running fine with no obvious signs of infection, but the MBR check still worries me. I have yet to enable any internet connections on this laptop until I feel confident it's clean. As such I can not test if the browser redirect is still an issue. The only time I've connected the laptop to an outgoing connection was when any tools needed to update.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    1. Run avenger.exe by double-clicking on it.
    2. Click OK at the warning to continue to use The Avenger
    3. Do not change any of the check box options!
    4. Shut down your protection software now to avoid possible conflicts.
    5. Copy everything in the Quote box below, and paste it into the Input script here: part of The Avenger
    6. Now click the [​IMG] button
    7. Click Yes to the prompt to confirm you want to execute.
    8. Click Yes to the Reboot now? question that will appear when The Avenger finishes running.
    9. Your PC should reboot, if not, reboot it yourself.
    10. A log file from The Avenger will be produced at C:\avenger.txt and it will pop-up for you to view when you login after reboot.
    11. Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )

    Are you missing any icons on your desktop? Are all your programs showing in Start / All Programs?

    What happened when you went into the recovery console and ran fixmbr? Did you get a warning message? Did you get a success message?

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * C:\MGlogs.zip
     
  6. chupon

    chupon Private E-2

    I have all my icons and start menu shortcuts.

    The fixmbr command back said it successfully replaced the MBR.

    Attached are the logs you requested.

    Thanks for your help. As this is not my machine I may have to make a decision for the owner soon to continue or just start over with a format. Do you know if this is something we would be able to clean up by next week? The owner needs a working machine and they came to me and I hoped I could fix it for them. I just don't want to give it back if it's not in 100% working condition.

    I appreciate your help on this but if you feel this is too big of an infection I can save us both time now. If you feel we are near completion we can continue.

    Again, thanks for your help.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Boot back into the RC and try doing the fixmbr command again. Then re-run MBRCheck and attach the new log.
     
  8. chupon

    chupon Private E-2

    Ok sorry for the delay.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use the CD to boot back into the Recovery Console, once there, type:
    map
    You should get a list, attach that to your next reply so I can see what path you are using.
     
  10. chupon

    chupon Private E-2

    C: 131072MB \Device\Harddisk0\Partition1
    D: \Device\CdRom0
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    OK, let's try again. Go back into the RC ( Using the CD!! ) and type this:
    fixmbr \device\harddisk0

    Reboot into normal mode and re-run MBRCheck. Attach the new log.
     
  12. chupon

    chupon Private E-2

    Ok here is the log.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This is disturbing. There is an outside chance that your faked MBR has somehow corrupted your Recovery Console disc, but it would be a first as far as I know.

    Can you use another computer to re-create that disc? The other option is to create a Hiram's disc.
     
  14. chupon

    chupon Private E-2

    The disc I am using is an XP install disc I've had awhile. I think it was a student copy I had obtained years ago.

    I noticed an odd error in the attached picture. I haven't seen this before. When I loaded the laptop it went into an automatic CHKDSK mode and I noticed it recovered some files. One was named Zlob which I know isn't a good sign. Does this offer any evidence on any next steps?

    If you think this is a lost cause I can just give it back to the owner and tell them to reformat.
     

    Attached Files:

  15. chupon

    chupon Private E-2

    I made a new recovery disc and re-ran the fixmbr command, but I fear the results were the same as the original XP disc. Here is the attached log.

    I am not familiar with a hiram's disc, could you give me instructions on that?
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    *** Please print these instructions ***

    1. Download Hiren's BootCD Iso to the desktop of a clean computer.
    2. Extract the zipped HirensBootCD.zip to your desktop.
    3. Open the extracted HirensBootCD folder and extract the zipped HirensBootCD.iso.
    4. Double click the BurnToCD.cmd bat file contained in the HirensBootCD folder. This will launch BurnCDCC.
    5. Insert a blank CD in your drive.
    6. Press Start. This will burn the image to disc. After it has completed...
    7. Restart your sick computer and boot from the HBCD you created.
    o If your PC is not booting from the CD, you need to change the boot order:
    + Restart your PC
    + As soon as you get an image, press the Setup key. This is usually F2, F10, F12 or Del. On some machines the key can also be a different one. It should, however, be stated on the screen which key is the setup key.
    + Once you enter the computer's BIOS, use the arrow keys and tab key to move between elements. Press enter to select an item to change.
    + Navigate to the tab, where you can set the boot order. It should be called Boot or Boot order
    + The tab should now show your current boot order.
    + If the CD-drive is not at the top, please navigate to the CD-Rom drive with the keys arrows. Then move it to the top of the list. The keys for switching boot position are usually + to move up and - to move down. However they can be different, but they should be stated in the help, so that you can find them easily.
    + Once the CD-drive is on top of the boot order, navigate to Exit and select Exit saving changes.
    o Your PC should now boot from your CD.
    o Click to select any options that are required to start the computer from the CD-ROM drive if you are prompted.
    8. When the CD boots choose "DOS BootCD".
    [​IMG]
    At the Hiren's BootCD main menu, select Next and hit Enter.
    [​IMG]
    At the second menu select 1 MBR (Master Boot Record)Tools
    [​IMG]
    In the list of MBR Tools select 1 MBR Work 1.08
    [​IMG]
    This screen will show the hard drive configuration.
    [​IMG]
    Type 5 to Install standard MBR code then hit Enter
    Type 1 to select Standard then hit Enter
    Type Y then hit Enter to confirm
    Type E then hit Enter to exit
    Press Ctrl+Alt+Del to restart the machine
     
  17. chupon

    chupon Private E-2

    Ok I am currently downloading the ISO, will take a little bit to download even with my broadband connection. I will keep you updated if anything doesn't work as intended.
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem.
     
  19. chupon

    chupon Private E-2

    Ok I ran all the steps without issue. I assume you want another MBRCheck log so I attached that.
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We are starting to see more and more MBR's that will not get fixed. The last resort is to reformat and re-partition the drive. Let me consult with the other Malware Fighters and see if we can come up with an alternative.
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  22. chupon

    chupon Private E-2

    Ok I ran the tool and it reported the system is clean. I was not given an option to perform any repair.

    MBR check still says the Code is Faked.
     

    Attached Files:

  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This is disappointing. Let me see if we can find something else.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds