Win32/Mebroot.K trojan help please

Discussion in 'Malware Help (A Specialist Will Reply)' started by sayros, Apr 1, 2010.

  1. sayros

    sayros Private E-2

    Hi there,

    This is my first post here. Followed all the steps in "Windows XP Cleaning Procedure" forum.

    Basically have had Win32/Mebroot.K trojan coming up for a while now (approx 1 month) on virus scan (Eset NOD32.) Didn't think too much of it as computer was functioning ok and was planning on getting a new one. Then one of my hard drives changed to "Local Disk" and wanted to format upon opening. I restarted and windows checkdisk recovered the master table and my drive label worked again and was able to open the drive. It started to happen every restart until finally the drive would not recover.

    Yesterday I googled around a bit and ran into a forum on what sounded like my problem and ran Dr.Web CureIt! This is the only thing I did to try and remove the Trojan before finding this forum. It said it found 1 infection and removed it.

    Today I followed all the steps in the READ & RUN ME FIRST. Malware Removal Guide. I am now posting my logs and hoping for some help.

    A couple more notes. Since I ran Dr.Web CureIt! yesterday, a second drive has become inaccessable. I am hoping to save the data on these two drives (E:, D:) These two are physical drives that I would like to put in my new computer but obviously would like to do so only when they no longer contain a virus or trojan.

    Windows XP SP3 is on F: partition right now. It is a very old version of windows and has tons of junk on it and I planned on just wiping it once I get my new computer and then merging it with C: Storage. C:Storage has all my most important files.

    Thanks in advance for any help. This is my first post. I hope this is not too long winded and somewhat clear. Please let me know if there is any other info you need. I have read the forum rules and guidelines and will follow advice specifically.
     

    Attached Files:

  2. sayros

    sayros Private E-2

    I can't post RRlog as it is 2.88 MB. Any recommendations?

    Basically it's :

    Path: E:\iTunes Music\Carlos Santana\shaman
    Status: Invisible to the Windows API!

    over and over again. I would assume it's because I have 2 drives (approx 30gb and 40gb) of files that I can't see in windows right now.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    According to the logs you attached, you do not have this infection. It would show if you did and also you would know it you had it because your PC would not be working too well. If Eset is really finding this somewhere other than in System Restore then you will have to attach a log from Eset showing exactly what and where.
     
  4. sayros

    sayros Private E-2

    Thanks for your response. I think the scans done with the programs suggested on this forum may have removed the trojan. What I'm left with though is 2 slave drives that I cannot access. Do you know how I might be able to recover these? I'm not sure what to post to show what's going on with the drives. I believe whatever I had affected the MFT of my drives. Windows Checkdisk can no longer recover them but recognizes the label from them. When I open "My computer" however, they both show as "local disks" and want me to format them whenever I try and open. Thanks again.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The scans done here did not find anything of significance and definitely did not find this infection. They really did not remove anything other than a couple of unnecessary files.

    No. It has nothing to do with what you did here. I suggest that you undo whatever you did on your own with Dr.Web or anything else. Perhaps you just removed a couple of autorun.inf files that you may need. I suggest that you post in the Software Forum for help with this.
     
  6. sayros

    sayros Private E-2

    Thanks for your help. I have done a complete scan with NOD32 and the win32/mebroot.k trojan is not found anymore.

    I have also posted in the software forum regarding the data loss on the 2 physical drives.

    Thanks again and happy easter!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Again try undoing what you did with other tools. Also try performing a System Restore to see if it gives you back access to your other drives.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds