Black Internet Virus - Help Required

Discussion in 'Malware Help (A Specialist Will Reply)' started by Moley, Aug 20, 2010.

  1. Moley

    Moley Private E-2

    Hi People,

    I'm in need of some help because if I have one more audio advert make me jump out of my skin my PC is is going to be flying out of my window.

    From what I've read on the web I believe I have the Black Internet Virus and I'd be really grateful if someone would guide me through removing it.

    I promise not to waste your time and I will respond to whatever I'm asked to do.

    Regards

    Moley
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some data on it
    • Right click on the screen and select > Select All
    • Press Control+C
    • Open a notepad and press Control+V
    • now please ATTACH that report to this thread

    Also I need to ask some questions:
    1. Do you have any drives that has a non-windows installation on them
    2. Are all drives NTFS formatted
    3. Do you have any non-standard or special MBRs which can occur from companies like Dell or HP who frequently install additional partitions used for recovery partitions in lieu of giving CD/DVDs.
    4. Is any program like Grub ( see:http://www.gnu.org/software/grub/ ) being used
    5. Is drive-encryption being used?
    6. Are any drives external USB pen drives or external hard drives being used?
    7. VERY IMPORTANT: Do you have all important data backed up? You really should do this before continuing since we will need to rewrite your MBR to fix this and while most times this can be done without any problem, these infections can react badly and that could result in a PC not being bootable. You really don't have much choice though since these infections are too dangerous to your security to leave on a PC.


    Now follow these instructions for running MGTools Using MGTools and then once finished attach the C:\MGlogs.zip
     
  3. Moley

    Moley Private E-2

    MBRCheck, version 1.2.3
    (c) 2010, AD

    Command-line:
    Windows Version: Windows XP Professional
    Windows Information: Service Pack 3 (build 2600)
    Logical Drives Mask: 0x020001fc

    \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
    \\.\D: --> \\.\PhysicalDrive0 at offset 0x0000000c`34f34a00 (NTFS)
    \\.\I: --> \\.\PhysicalDrive5 at offset 0x00000000`00007e00 (FAT32)

    Size Device Name MBR Status
    --------------------------------------------
    465 GB \\.\PhysicalDrive0 Known-bad MBR code detected (Whistler / Black I
    nternet)!
    SHA1: 4ECC3C3B1681F21372ABA4F582251838559E85CD
    465 GB \\.\PhysicalDrive5 RE: Unknown MBR code
    SHA1: 639AC5CDF8A5CF3245975932C6A4215450A7B98F


    Found non-standard or infected MBR.
    Enter 'Y' and hit ENTER for more options, or 'N' to exit:


    Ans Q1: Only Windows on this machine

    Ans Q2: C:\ and D:\ = NTFS I:\ = FAT32 This is my external hard drive which I backup to. I'll remove this

    Ans Q3: As far as I'm aware No.

    Ans Q4: No

    Ans Q5: I have 1 folder encrypted using Trucrypt

    Ans Q6: 1 external HD which i never leave connected and I use a USB wireless key for my wifi

    Ans Q7: All my files are backed up to the external HD
     
  4. Moley

    Moley Private E-2

    MBR report Attched
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Don't forget the log from MGTools :)
     
  6. Moley

    Moley Private E-2

    Running MGTools now. Seems to be hanging a bit on Running analyse.exe

    By the way, thanks for your help.
     
  7. Moley

    Moley Private E-2

    MGlogs.zip Attached.

    I did get the error relating to .NET Framework not being installed however, the prgram seemed to complete ok without it.

    I shall install the .net framework in case needed at a later date.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now if you wish to continue and fix the malware - please do the following:
    • Run MBRCheck.exe
    • Wait until you see the following lines:
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
      • Options:
        [1] Dump the MBR of a physical disk to file.
        [2] Restore the MBR of a physical disk with a standard boot code.
        [3] Exit.
        Enter your choice:
    • Please push the 'Y' key and then press Enter
    • When the program asks you to Enter your choice: enter 2 to Rstore the MBR and press the Enter key
    • Now the program will ask you to "Enter the physical disk number to fix (0-99, -1 to cancel):"
      • Enter 0 and press the Enter key.
    • The program will show Available MBR codes as below
    • You need to select your version of Windows frrom the list. For example, enter 0 or 1 for XP or enter 3 for Vista.....etc. and then press Enter.
    • The program will prompt for confirmation. Type 'YES' and hit Enter.
    • Left click on the title bar (where program name and path is written). From menu chose Edit -> Select All
    • You will see all the text in the window get highlighted.
    • Hit the Enter key on your keyboard to copy all of the text into the clipboard.
    • Paste that text into Notepad, save it to your desktop as MBRfix.txt
    • Restart your PC.
    • Attach the MBRfix.txt file to your next message..
    Also tell me how things are working.
     
  9. Moley

    Moley Private E-2

    Thank you for the advice. I'll try this first thing in the morning and get back to you.

    Cheers

    Moley
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Okay. I'll be here waiting.
     
  11. Moley

    Moley Private E-2

    I have run the MBRcheck.exe and my machine appears to be working fine.

    Attached is the MBRfix.txt file as requested.

    Thank you so much for your help. Your a legend.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run MBRCheck.exe again


    Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this. Also attach the new log from MBRCheck.
     
  13. Moley

    Moley Private E-2

    I ran the MBRCheck.exe again. The subsequent report is attached.

    I then tried to run Avenger as you described but got the error message shown in AvengerError1.jpg

    I aborted avenger.

    Have I missed a step?

    Moley
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Use windows explorer to find and delete the below folders if they exist:

    Do not forget to attach the new log from MBRCheck!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  15. Moley

    Moley Private E-2

    The fixME.reg file completed successfully.

    Attached is the MGlogs.zip as requested.

    The following post will have the MBRcheck info. I seem to be having trouble attaching more than 1 file to a post.

    Mopley
     

    Attached Files:

  16. Moley

    Moley Private E-2

    The forum states that I have already uploaded the MBRcheck do and doesn't seem to post it with my reply. I have tried renaming the doc etc. and it doesn't seem to work.

    Sorry
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That just means you are trying to attach the old log, please attach the new log from running MBRCheck.exe again .
     
  18. Moley

    Moley Private E-2

    Do you want me to run through the options again? Restore of a physical disk, select opt 1 for xp etc?
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I just want you to do this:

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some data on it
    • Right click on the screen and select > Select All
    • Press Control+C
    • Open a notepad and press Control+V
    • now please ATTACH that report to this thread
     
  20. Moley

    Moley Private E-2

    As requested.

    Regards,

    Moley
     

    Attached Files:

  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You will need to boot to the Recovery Console to remove this infection.

    Now boot to the Recovery Console and run the fixmbr to clear a Master Boot Record infection that you have.

    You can read the below to help you do this:

    http://support.microsoft.com/kb/307654


    Then boot back into normal mode.

    Then re-run MBRCheck again and attach the new log.
     
  22. Moley

    Moley Private E-2

    Hi TimW,

    Sorry for the slow response, couldn;t find my XP disc. Ran the recovery as described and this is the result!

    MBRCheck, version 1.2.3
    (c) 2010, AD

    Command-line:
    Windows Version: Windows XP Professional
    Windows Information: Service Pack 3 (build 2600)
    Logical Drives Mask: 0x020000fc

    \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
    \\.\D: --> \\.\PhysicalDrive0 at offset 0x0000000c`34f34a00 (NTFS)

    Size Device Name MBR Status
    --------------------------------------------
    465 GB \\.\PhysicalDrive0 Windows XP MBR code detected
    SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A


    Done!
    Press ENTER to exit...
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That should have taken care of any malware issues you were having. Tell me how things are running.
     
  24. Moley

    Moley Private E-2

    Everything seems to be running fine. No more audio adverts and no more constant windows click click click.

    Thank you for all your help
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds