Bootkit Infection or Possibly Custom Boot Manager Installed-ongoing issue for months

Discussion in 'Malware Help (A Specialist Will Reply)' started by maninthebox, Oct 10, 2010.

  1. maninthebox

    maninthebox Private E-2

    Hello, I’ve been having pretty major issues with my computer over probably the past 4-5 months. As I’ve concluded from my research many others are having the same or similar problems as I am. I think I know what is wrong I just really need really in-depth help on how to fix it. I’ve followed other instructions on this site on how to solve this problem with no success. (I downloaded bootkit remover and the results showed I had an unknown boot code. Which means either there’s an active bootkit infection, or a custom boot manager installed. Not that I really know what any of this means…) When I tried entering in the run box what the instructions directed me to it said ‘error cannot find…etc.’.

    The problems that keep occurring are:
    Random audio in the background in the form of ads like every few minutes or so, clicking noises, slower system performance, and loss of attention to a program every few seconds (for example- if I am trying to type the arrow will loss focus as if I just opened another program on top of microsoft word).

    Other potentially helpful info:
    -Operating system: MS Windows XP Professional 32-bit SP3
    -Primary Browser: Mozilla Firefox (I don’t use Internet Explorer AT ALL)
    - I have a Toshiba external hard drive which I did not include in all the searches. However, bootkit remover already said my internal hardrive C is the one which is infected. (I’ve used this hardrive while working offline with no problems.)

    In order to avoid these errors I’ve only found one solution and that is to unplug my wireless receiver from my computer as soon as I turn it on. And if I need to use the internet I can only plug the receiver in for 10 minute intervals being that after about 20 minutes with the internet connected will result in all the above issues. So basically I’ve been using my computer offline for months. I’ve tried next to everything I’m capable of with my level of computer literacy – which isn’t very good. (It’s very hard to follow any kind of instructions when you don’t understand at all what is being explained.)

    So I finally have decided it was time to take an entire day to solve this problem. I’ve followed ALL of the site instructions and have gotten all of the appropriate logs.
    NOTE: COMBOFIX Deleted ‘bootkit whistler’ but I don’t know if that means my problem is solved??
    NOTE: MGtools had an error while running but still produced the log

    A final question: if I’ve entered any private information while online in the past months could it have been stolen like a keylogger steals information by seeing what you type?

    Thanks in advance for any help. Any input would be highly appreciated just keep in mind I’m not that computer literate. I have many files of interest on this computer and I really need to solve this so thanks.
     

    Attached Files:

  2. maninthebox

    maninthebox Private E-2

    Re: Bootkit Infection or Possibly Custom Boot Manager Installed-ongoing issue for mon

    Final log out of the 5
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Re: Bootkit Infection or Possibly Custom Boot Manager Installed-ongoing issue for mon

    Welcome to MajorGeeks, maninthebox.

    Investigating your logs should reveal that.

    Not typical of a master boot infection - I'll see what shows in your logs.

    I am currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Our queue is working the oldest threads first.

    Thanks for your patience.
    dr.m
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Re: Bootkit Infection or Possibly Custom Boot Manager Installed-ongoing issue for mon

    Hello, maninthebox

    Why am I not seeing protection software installed on this machine?

    You should review this thread:
    Warning about Porn, Keygens, Cracks, and other Illegal Software


    *Your SUPERAntiSpyware's definition database were behind.
    • Run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new "Complete scan" of your system. And attach this new log.

    Other than the tools our guide instructed you to save there, I strongly recommend that you clean up this account's Desktop immediately leaving only shortcut links. [ C:\Documents and Settings\Owner\Desktop ] Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least - it can have an effect on your PCs performance.

    Step 1:
    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Make sure you have shut down all protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text inside of the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:
    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Step 2:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 3:
    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.

    Step 4:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • C:\MGlogs.zip
    • MBRCheck.txt log
    • updated SASlog.txt

    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    dr.m
     
    Last edited by a moderator: Oct 11, 2010
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: Bootkit Infection or Possibly Custom Boot Manager Installed-ongoing issue for mon

    Also, see these instructions to change your proxy settings:
    Change Proxy Settings.

    @Dr.M, according to his runkeys log, the MBR is fine. :)
     
    Last edited: Oct 11, 2010
  6. maninthebox

    maninthebox Private E-2

    Re: Bootkit Infection or Possibly Custom Boot Manager Installed-ongoing issue for mon

    Hi sorry for the late response I've been very busy. So far from what i can tell the major issues i stated in my first request have not occured since running combofix the first time.

    @timw, i do not know to get the information to fill out the settings in order to change my proxy to a manual setup

    @dr.moriaty, i followed your instructions and have attached the logs you requested
     

    Attached Files:

  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Re: Bootkit Infection or Possibly Custom Boot Manager Installed-ongoing issue for mon

    Those logs look good, maninthebox..

    * We'll fix that "ProxyServer" entry another way:

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the new C:\MGlogs.zip file to your next reply.

    dr.m
     
  8. maninthebox

    maninthebox Private E-2

    Re: Bootkit Infection or Possibly Custom Boot Manager Installed-ongoing issue for mon

    Here is the requested log.I also had a question, i downloaded the program 'killbox' hoping i would be able to delete two back up folders I've had on my hardrive which i do not need. it was unsuccessful in deleting these folders, so how can i remove them?

    Also about cleaning up my desktop i know a had some exe. files but most of the things on there are just shortcuts to programs i use, so is this a bad thing?
     

    Attached Files:

  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Re: Bootkit Infection or Possibly Custom Boot Manager Installed-ongoing issue for mon

    What are the full file pathways to them? What created them? Are they somehow protected?

    Shortcuts/links are fine, you did a good job cleaning up.

    *Your logs look good.
     
  10. maninthebox

    maninthebox Private E-2

    Re: Bootkit Infection or Possibly Custom Boot Manager Installed-ongoing issue for mon

    i created one of them. and i got this computer from a freind and the other backup is his. whenever i try to delete them it says that they are either protected or something within the folders is in use.
     
  11. maninthebox

    maninthebox Private E-2

    Re: Bootkit Infection or Possibly Custom Boot Manager Installed-ongoing issue for mon

    Also what do you recommend as FREE protection software? Also when i go to connection settings for firefox "manual" proxy is still not selected so is there still a problem with my proxy settings?
     
  12. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Re: Bootkit Infection or Possibly Custom Boot Manager Installed-ongoing issue for mon

    Hello, maninthebox

    Your logs are clean and you can ask about your remaining issues in our

    Software Forum

    Networking Forum

    Recommendations for FREE protection software are given in the last link below:

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work through the below link:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
  13. maninthebox

    maninthebox Private E-2

    Re: Bootkit Infection or Possibly Custom Boot Manager Installed-ongoing issue for mon

    Thanks a lot dr.moriarty, i would have been lost without your help. I really appreciate your step-by-step aid. Thanks again:)
     
  14. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Re: Bootkit Infection or Possibly Custom Boot Manager Installed-ongoing issue for mon

    ;)

    You're very welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds