Help with rootkit

Discussion in 'Malware Help (A Specialist Will Reply)' started by bradica, Jul 8, 2013.

  1. bradica

    bradica Private E-2

    Hi,
    my friends laptop was getting BSOD everytime while loading Windows, so I took it's hard drive and connected it to my laptop and scanned it with Kaspersky AV. It found rootkit.boot.sinowal.b and removed it, but now it shows that there's nothing on the disk. I think that my system is safe, but i don't know how to fix this external drive. Please help me and thanx in advance...
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Put the hard drive back into the computer it came out of and do the following:

    Please do the below so that we can boot to System Recovery Options to run a scan. There will be two options to choose from. One if you do not have your Windows 7 boot DVD and another when you have your DVD.

    For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Option1: Enter System Recovery Options from the Advanced Boot Options:

    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    Option2: Enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  3. bradica

    bradica Private E-2

    It's windows XP on infected computer... Is the procedure the same?
    And i don't have Repair your computer menu item in Advanced Boot Options.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No, it doesn;t work on XP. Your best bet at this point is going to be a reinstall. :(
     
  5. bradica

    bradica Private E-2

    what about FIXMBR option? is it safe to try before reinstall?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What drive are you trying to boot to? Your MBRCheck shows your main drive is Windows 7, and the faked MBR is another partition. Is that the one you are trying to fix? Can you not boot to Win.7?
     
  7. bradica

    bradica Private E-2

    I have done MBRCheck on another computer, so main drive with Windows 7 is on non-infected computer. On infected one is hard drive that has Windows XP on it. Those were 2 hard drives, not 2 partitions...
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now I understand. You still have it slaved.

    Do you have all important data backed up? You really should do this before continuing since we will need to rewrite your MBR to fix this and while most times this can be done without any problem, these infections can react badly and that could result in a PC not being bootable. You really don't have much choice though since these infections are too dangerous to your security to leave on a PC.

    Also note if you have a Dell PC which uses a non-standard MBR ( or another manufacturer's who does similar to Dell) , fixing the mbr may prevent access the the Dell Restore Utility, which allows you to press a key on startup and revert your computer to a factory delivered state. There are a couple of known fixes for said condition, though the methods are somewhat advanced. If you are unwilling to take such a risk, you should not continue but you risk serious problems leaving this infection in place and thus your only other option would be to try using the Dell Restore Utility to return a factory ship state which will remove everything you additional you have put onto the PC.


    Now if you wish to continue and fix the malware - please do the following:

    * Run MBRCheck.exe
    * Wait until you see the following lines:
    o Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    o Options:
    [1] Dump the MBR of a physical disk to file.
    [2] Restore the MBR of a physical disk with a standard boot code.
    [3] Exit.
    Enter your choice:

    * Please push the 'Y' key and then press Enter
    * When the program asks you to Enter your choice: enter 2 to Restore the MBR and press the Enter key
    * Now the program will ask you to "Enter the physical disk number to fix (0-99, -1 to cancel):"
    o Enter 1 and press the Enter key.
    * The program will show Available MBR codes as below

    * You need to select your version of Windows from the list. For example, enter 0 or 1 for XP or enter 3 for Vista.....etc. and then press Enter.
    * The program will prompt for confirmation. Type 'YES' and hit Enter.
    * Left click on the title bar (where program name and path is written). From menu chose Edit -> Select All
    * You will see all the text in the window get highlighted.
    * Hit the Enter key on your keyboard to copy all of the text into the clipboard.
    * Paste that text into Notepad, save it to your desktop as MBRfix.txt
    * Restart your PC.
    * Attach the MBRfix.txt file to your next message..

    Now please re-run MBRCheck.exe and attach that log also.
     
  9. bradica

    bradica Private E-2

    So I should now put infected hard drive (From HP Compaq 6720s, manufacturer is Toshiba) in non infected laptop and do this procedure or?

    And can this procedure do anything to my laptop (non-infected)?

    And I don't see how can i backup data on infected hard drive, because I can't do anything with it?

    Sorry for so many questions... :)
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Since you ran MBRCheck with the drive slaved, keep it that way and run the procedure. MBR identified the slave drive as drive 1, so it will not affect the Win7 drive.
     
  11. bradica

    bradica Private E-2

    I have done it, but it seems the same...
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's try a different approach.
    Put the drive back into the original computer.
    1. Insert the Windows XP CD-ROM into the CD-ROM drive.
    2. Restart the computer from the CD-ROM drive.
    3. Press R to start the Recovery Console when the "Welcome to Setup" screen appears.
    4. Select the installation that you want to access from the Recovery Console.
    5. Enter the administrator password and press Enter.
    6. Type the following command and press Enter:
    fixmbr
    7. Following the onscreen instructions to restore the Master Boot Record.
    8. Type exit
    9. Press Enter. The computer will now restart automatically.

    Does it now boot up?
     
  13. bradica

    bradica Private E-2

    I couldn't do anything... When i started Recovery Console, I got message "Setup did not find any hard disk drives installed in your computer..."
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'm afraid you will have to do a clean install. :(
     
  15. bradica

    bradica Private E-2

    ok... thanx for your help...
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry I couldn't be of better assistance. If you need help reinstalling, post in the software forum. And good luck. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds