Rootkit; factory reset; hopeless

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Katertot, Nov 26, 2011.

  1. Katertot

    Katertot Private E-2

    Okay, so I had some malware on my computer, I was able to get malwarebytes and get rid of them.

    I thought I was good for awhile until Windows Explorer started crashing a lot and I realized every time I was on google, I would get redirected. I had read somewhere that one of the malwares I had (which by the way were two fake scanners) sometimes comes with rootkits. So I did a rootkit scan with my avg 12, and well, there it was. But it wasn't able to get rid of it because it's hidden.

    I've tried avg, I've tried zero.access\max++ remover tool, I've tried combofix (which was what told me it was Zero.Access rootkit), I've tried tdsskiller, and at this point I was pretty hopeless. So I decided to try to reset my pc. I couldn't figure out how to save my life, then I saw a video of someone who showed the entire process for resetting it for windows 7, which is what I have. Basically it showed going into the f8 options, and then choosing Repair Your Computer, and that a box would show after starting up offering different options to repair it, along with resetting to factory settings.

    Well, it's stuck at the "Windows is loading files..." screen with the big white bar underneath. I haven't touched it in over half an hour and it's still there.

    I'd rather not lose all my media, but at this point I don't know what else to do. Can anyone help?

    My dad built the computer himself, so I don't even know what it is (dell, hp, acer, ect), and it's running Windows 7. I've pretty much kept my Internet disconnected anytime it's on because of the rootkit.
     
  2. Katertot

    Katertot Private E-2

    Just an update: I left the "Windows is loading files..." screen running over night, and when when I woke up this morning, it was still there... I tried hitting escape, did nothing, so I did ctrl+alt+del, and it restarted it. I'm really not sure what to do from here. I basically just need help on either getting rid of the rootkit or figuring out how to reset my pc.
     
    Last edited: Nov 26, 2011
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please follow these instructions:

    READ & RUN ME FIRST. Malware Removal Guide

    Also do this:
    Please also download MBRCheck to your desktop.

    See the download links under this icon [​IMG]

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  4. Katertot

    Katertot Private E-2

    Alright, I did all the scans and whatnot, or at least the ones I could do. I was not able to work with combofix. I started running it, I had removed AVG and I had nothing else running, followed all the directions, and I let it sit at the scanning screen over night. I left it alone because I know how long it can take because I've ran it before (it didn't find anything when I did run it before), and I ended up falling asleep so it had all night to run. When I woke up this morning, it was still at the first scanning part, and didn't even start any of the stages. The last time I ran it, it took around 1-2 hours to complete everything. This isn't the first time I've tried running Combofix and this has happened.

    Also, I have a log from RootRepeal, but it's not the actual log. It wouldn't let me scan anything and kept saying there were all kinds of errors. It let me save it as a log, saying what the errors were, so I'm attaching that so you can see what I saw. By the way, it popped up right when I opened RootRepeal saying there were errors. I hadn't tried to scan anything yet.

    And two more things. I don't know if this will help or not, but when I initially did a rootkit scan on AVG, way before I even came to MG for help, when AVG would detect the rootkit, it would say: IRP hook, \Drivers\atapi IRP_MJ_INTERNAL_DEVICE_CONTROL -> 0x89E85FA9
    But it will say the object is hidden.

    And the last thing, I'm not sure if this has anything to do with my computer being infected, but lately I've noticed on my desktop, different urls will kind of pop up on the left hand side of the screen. Mostly, if not all, mevio.com urls.
     

    Attached Files:

  5. Katertot

    Katertot Private E-2

    And here is the MBRCheck log.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Preferably from a clean computer, I need you to download: gparted-live-0.10.0-3.iso (115.1 MB)
    Windows 7 32-Bit (x86) Recovery Environment

    Create a bootable CD, 1 for Gparted and 1 for the Windows 7 Recovery Enviroment, from the ISO images. You can use ImgBurn do this.

    Now boot off of the newly created Gparted CD.

    [​IMG]
    You should be here...
    Press ENTER

    [​IMG]
    By default, "do not touch keymap" is highlighted. Leave this setting alone and just press ENTER.

    [​IMG]
    Choose your language and press ENTER. English is default [33]

    [​IMG]
    Once again, at this prompt, press ENTER

    You will now be taken to the main GUI screen below
    [​IMG]
    According to your logs, the partition that you want to delete is Partition Size 1.83 MB (1,916,928 bytes)
    Click the trash can icon to delete and then click Apply.

    You should now be here confirming your actions:
    [​IMG]

    Now you should be here:
    [​IMG]

    [​IMG]
    Is "boot" next to your OS drive?

    If "boot" is not next to your OS drive under "Flags", right-mouse click the OS drive while in Gparted and select Manage Flags

    In the menu that pops up, place a checkmark in boot like the picture below:
    [​IMG]

    Now double-click the [​IMG] button.

    You should receive a small pop up like this:
    [​IMG]
    Choose reboot and then press OK.

    Now reboot from the Windows 7 Recovery Environment CD and execute the following commands:


    • bootrec /FixMbr
    • bootrec /fixboot
    • exit


    Once back in Windows.

    Download MBRCheck.exe to your desktop.

    • Be sure to disable your security programs
    • Double click on the file to run it (Confirm the UAC prompt)
    • A window will open on your desktop
    • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
    • If nothing unusual is found just press Enter
    • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
    • Attach that file.
     
    Last edited by a moderator: Nov 28, 2011
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should not have bittorrent running at start up, as it may be how you got infected!!

    Once you have completed those steps, if you can't boot it up, go back to the disc for the Win7 recovery environment and do the first item: start up repair. Then see if you can boot to normal mode.

    Once you are up and running again, download The Avenger by Swandog46 to your Desktop.

    See the download links under this icon [​IMG]
    Extract avenger.exe from the Zip file and save it to your desktop.


    1. Run avenger.exe by double-clicking on it.
    2. Click OK at the warning to continue to use The Avenger
    3. Do not change any of the check box options!
    4. Shut down your protection software now to avoid possible conflicts.
    5. Copy everything in the Quote box below, and paste it into the Input script here: part of The Avenger
    6. Now click the [​IMG] button
    7. Click Yes to the prompt to confirm you want to execute.
    8. Click Yes to the Reboot now? question that will appear when The Avenger finishes running.
    9. Your PC should reboot, if not, reboot it yourself.
    10. A log file from The Avenger will be produced at C:\avenger.txt and it will pop-up for you to view when you login after reboot.
    11. Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  8. Katertot

    Katertot Private E-2

    What of I don't have a clean computer to download those? And should I just get rid of BitTorrent?
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just go ahead and download and create the disc's on your computer. And yes, I would stop bittorrent from loading at startup. I can give you a script to remove it once we get you back up and running.
     
  10. Katertot

    Katertot Private E-2

    Do you think it would be better to download them in safemode? Or would that not matter? Sorry for so many questions! Just don't wanna make anything worse!
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If all you can do is safe mode, then yes, try to create them in that mode.
     
  12. Katertot

    Katertot Private E-2

    So, apparently I can't download the Recovery Environment because of insufficient privileges. I even created an account to see if that's why I couldn't see it, but it won't let me go to the page regardless. Is there somewhere else I can get it from?

    "1. Your user account may not have sufficient privileges to access this page. Are you trying to edit someone else's post, access administrative features or some other privileged system?
    2. If you are trying to post, the administrator may have disabled your account, or it may be awaiting activation."

    And I did get it activated as well.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you having this issue on MG's or is your system not giving you privileges? Can you get access to a different computer to download and create the discs?
     
  14. Katertot

    Katertot Private E-2

    When I click on the link for the Windows 7 32-Bit Recovery Environment, it leads to a page on Digiex that says I don't have permission to view the page. I tried creating an account to see if that was the problem, and it still wouldn't let me view it. I attached screen shots of the pages, both logged in and out.
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Crap, they must have pulled their links. Try this one:
    Windows RC .iso

    Make sure you use the Win7 32 bit download.

    EDIT: That isn't working either. Hang on.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  17. Katertot

    Katertot Private E-2

    I hope you can get back to me soon, because now I'm stuck. I did everything up the second command prompt after booting up with the windows disc. There was no "boot" under the flags during Gparted boot, so I just went and finished it. I did the bootrec /FixMbr prompt and it said that it was completed successfully. But when I try to do the bootrec /fixboot prompt, it says "Element not found."

    Did I do something wrong? I don't know what I should do from here.
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Had you already removed the faked partition? Are you able to boot to normal mode now? If not, you may need to boot back to the Recovery Environment and run the first item ; Repair the start up. Tell me what is happening.
     
  19. Katertot

    Katertot Private E-2

    Alright, yes I did already removed the fake partition. I was able to get Windows to boot into normal mode. I just had to do the Startup Repair. I also have the logs from MBRCheck, The Avenger, and MGTools attached. I went and ran the programs like you normally said to after all the booting. I hope that it was okay to go ahead and do that and that I didn't screw anything up.
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks like you are good to go. :)

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0


    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  21. Katertot

    Katertot Private E-2

    Thank you so much! I'm not having any problems anymore as of now. I'll definitely keep my eyes wide open for the next couple of days, just in case. If anything else happens, I'll come straight to MG!
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds