MBR infection and virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by scurrg, Jun 26, 2013.

  1. scurrg

    scurrg Private E-2

    Hello, was getting frequent BSOD recently, investigated and found my HP Recovery utility was not loading (freezing)...hmmm problems. Running Windows 8 on hp 650.
    At the same time Norton Framework dissappeared from Prog x64 files. System restore points missing. Ran MBAM and it detected virus and thats how I have ended up here. Ran Mbrcheck and it is infected . Have included all logs except MBAM which is the first I ran that detected the virus. MBAM I ran today came out clear. Hope that it can be fix as was networked with wifes HP and appears hers may be infected as well. Have killed networking from this computer and hers Will deal with this first though. Thank you in advance
     

    Attached Files:

    Last edited by a moderator: Jun 26, 2013
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the log from running MBRCheck.
     
  3. scurrg

    scurrg Private E-2

    hello attached is the MBR check log


    \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`31500000 (NTFS)
    \\.\D: --> \\.\PhysicalDrive0 at offset 0x0000006f`41000000 (NTFS)

    PhysicalDrive0 Model Number: HitachiHTS545050A7E380, Rev: GG2OA7A0

    Size Device Name MBR Status
    --------------------------------------------
    465 GB \\.\PhysicalDrive0 Unknown MBR code
    SHA1: 639AC5CDF8A5CF3245975932C6A4215450A7B98F


    Found non-standard or infected MBR.

    Thanks again
     
    Last edited by a moderator: Jun 27, 2013
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually this is not an attachment. This is an inline log. Please do not post inline logs. Always make attachments as in your first message. I deleted most of your inline log except the important data.

    There is nothing wrong with your MBR. MBRCheck is just old and does not understand Windows 8. Actually it has problems with quite a few non-standard MBRs.

    Also RogueKiller will report Empty MBR Code on Windows 8 systems
     
  5. scurrg

    scurrg Private E-2

    Sorry about that, am new to this service and appreciate it very much. Funnily enough that was what I first thought about the unknown MBR, it was just after MBAM and Hitman reported probs I assumed I must be wrong.

    Will await next steps and follow advice properly next time....
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No they did not really find anything. What was in the MBAM log is just something you downloaded.

    Your BSOD are probably unrelated to malware.

    The only issue I observed on a quick look is that you have stuff from Webroot SecureAnyWhere showing but it does not seem to be installed per your logs.
     
  7. scurrg

    scurrg Private E-2

    Thank you for the reply, does that mean I need do anything else as far as malware?
    If so is there anyway to track down what caused BSOD and if there are any other ways of resolving without having to refresh my PC from F11 on boot up to refresh using HP refresh as i can access recovery manager on boot but not as desktop app.

    So very much appreciate the time you give me:)
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    No. Your logs are clean, but I do need to give you the below final instruction to cleanup from what we did in the READ & RUN ME FIRST.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:


    I suggest posting in the Software Forum. Provide them the details and error message/number info. You may want to first also try uninstalling that WebRoot SecureAnywhere software to see if it is somehow causing a problem.
     
  9. scurrg

    scurrg Private E-2

    I would like to thank you so much for giving me your time. As a further development I stumbled on an article on MS website regarding super Tuesday update "KB2821895 Windows 8 x64 Update 06.11.2013 problem".
    It appears that this was what had been causing the BSOD and apparent loss of data etc leading me to assume malware.
    I have since followed the advice to access elavated command prompt and type "DSIM /online /cleanup-image/ restorehealth" then enter, wait about 1hr for it to do its thing then type "sfc /scannow" then enter, let it do its thing , reboot and hey presto system back as far as i can tell.
    Apparently this is a major bug with win 8 x64 and as yet MS haven't pulled their heads out of the sand. It also says if you can access Sys Restore prior to update 13/06/13 then that is an option and then hide the update from windows uodate survice (If thats what they want to call it).

    I am still unable to chkdsk /f without it getting to 38% restart then pop up 100% and login and there appears to be a couple of missing files still but on the whole 110% improvement and rarely 100% disc write now.

    Thanks again and will try to solve the rest unless you can point me in the right direction...

    :)
     
  10. scurrg

    scurrg Private E-2

    Sorry about typo but the first command should be DISM /Online /Cleanup-Image /RestoreHealth. Thanks again
     
  11. scurrg

    scurrg Private E-2

    I also just noticed last comment of yours to post to software forum so thanks again for your time
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Yes there are issues with that Windows 8 update.

    KB2821895 Windows 8 x64 Update 06.11.2013 problem

    Seems that some people think two DISM commands need to be run. Others say none of this helped. I have no opinion on it yet as I had already blocked that update on my Win 8 PC.
     
  13. scurrg

    scurrg Private E-2

    I have since realized that you are correct and that the 2 DISM method was a better option for me after ! more BSOD. As the ms forum stated this is a work around only and hopefully MS will provide a patch fix for us who unfortunately installed it.

    Hope this helps others out there suffering the same frustrating prob. Thankyou again.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Yes I'm sure that quite a few people have already had problems with the update. And some may have also suspected malware like you. ;) Happy to hear my assertion was correct and also that at least you have it working to some level now. The rest is up to Microsoft.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds