infected...

Discussion in 'Malware Help (A Specialist Will Reply)' started by rattlsnak, Mar 8, 2011.

  1. rattlsnak

    rattlsnak Private E-2

    Hello everyone. A few weeks ago I picked up something that was redirecting my IE and FF browsers and also I kept getting pop ups from ESET stating that various threats were trying to run and are being blocked. I *think* I picked something up through Java as most of the threats were of the JAR variety, but not all.

    I ran through all the malware procedures here: http://forums.majorgeeks.com/showthread.php?t=35407
    for my XP system and the browser redirects and all but one threat seem to be gone now.

    The remaining threat, as noted by ESET is:

    object: MBR sector of the 0. physical disk
    threat: Win32/Olmarik.AJL trojan

    As described in the above procedure, here are my logs:
     

    Attached Files:

  2. rattlsnak

    rattlsnak Private E-2

    and the last log from MG tools:

    NOTE: I do not have a file called 'MGlogs.zip' anywhere in the MGtools folder, so I attached the filelog text file. If that is not right, please let me know how to find the correct file.


    Thanks in advance!
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    MGLogs.zip will not be found in the MGTools folder. It is here: C:\MGLogs.zip.

    Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!


    Be sure to download TDSSKiller.exe (v2.4.0.0) from Kaspersky's website and not TDSSKiller.zip which appears to be an older version 2.3.2.2 of the tool.

    • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
      Vista/Windows 7 users right-click and select Run As Administrator.
    • If TDSSKiller does not run, try renaming it. To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123tdk.com).
    • Click the Start Scan button.
    • Do not use the computer during the scan
    • If the scan completes with nothing found, click Close to exit.
    • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_14.17.05_log.txt) will be created and saved to the root directory ( usually Local Disk C ).
    • Attach this log to your next message


    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...

    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.
     
  4. rattlsnak

    rattlsnak Private E-2

    Thanks for the quick reply. I had run the TDSS and MBR a few days earlier, but I have run them again as you have requested. Below are the logs from today.

    And I have also included the MGLogs.zip folder.

    Thanks,
    M.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Tdsskiller did find the infection. However, it seems that according to MBRCheck, you now have a Win 98 MBR. :confused

    * Run MBRCheck.exe
    * Wait until you see the following lines:
    o Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    o Options:
    [1] Dump the MBR of a physical disk to file.
    [2] Restore the MBR of a physical disk with a standard boot code.
    [3] Exit.
    Enter your choice:

    * Please push the 'Y' key and then press Enter
    * When the program asks you to Enter your choice: enter 2 to Restore the MBR and press the Enter key
    * Now the program will ask you to "Enter the physical disk number to fix (0-99, -1 to cancel):"
    o Enter 0 and press the Enter key.
    * The program will show Available MBR codes as below

    * You need to select your version of Windows from the list. For example, enter 0 or 1 for XP or enter 3 for Vista.....etc. and then press Enter.
    * The program will prompt for confirmation. Type 'YES' and hit Enter.
    * Left click on the title bar (where program name and path is written). From menu chose Edit -> Select All
    * You will see all the text in the window get highlighted.
    * Hit the Enter key on your keyboard to copy all of the text into the clipboard.
    * Paste that text into Notepad, save it to your desktop as MBRfix.txt
    * Restart your PC.
    * Attach the MBRfix.txt file to your next message..

    Now please re-run MBRCheck.exe and attach that log also.
     
  6. rattlsnak

    rattlsnak Private E-2

    I tried numerous times, but every time I run MBRCheck it goes straight into the program and then says "done! Hit enter to exit" I never have an chance to get into the options as you listed. In other words, I never see the line "Enter 'Y' and hit ENTER for more options, etc."

    * Run MBRCheck.exe
    * Wait until you see the following lines:
    o Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    o Options:
    [1] Dump the MBR of a physical disk to file.
    [2] Restore the MBR of a physical disk with a standard boot code.
    [3] Exit.

    Interesting because the threat I keep getting is in the MBR section of my physical drive.

    Grasping at straws here, but could it be that the laptop was originally loaded with W98 or such? I did buy it brand new and XP was on it when I got it new, but just wondering.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have your XP install disc? If you do, boot to the Recovery Console and when there, type this:

    FIXMBR

    You can read the below to help you do this:

    http://support.microsoft.com/kb/307654


    Then boot back into normal mode.

    Then try to run MBRCheck again to see if it is fixed.
     
  8. rattlsnak

    rattlsnak Private E-2

    TimW, I do not have an XP install disc. I don't remember if it came with one or not, but anyway I don't have one now.

    Any other work a-rounds? And is this considered some type of malware, or according to the logs, am I basically clean now?
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This is a download of an .iso file of just the Recovery Console for XP.
    Burn to CD with Nero or other 'disc image' capable tool and boot.

    XP Recovery Console.

    Then try to boot into the Recovery Console and run the fixmbr command.
     
  10. rattlsnak

    rattlsnak Private E-2

    ok, will do.. I will have to wait until tomorrow, but I will report back.
    Thanks greatly for your time.
    M.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem. I am just concerned that MBRCheck reported the Win 98 MBR. That is just weird and I would like to try to fix that before we are done. ;)
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I have checked with my colleagues and the consensus is to leave it alone. ;)
     
  13. rattlsnak

    rattlsnak Private E-2

    ok, so to confirm, do not do the XP recovery console procedure?
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Correct. We are assuming that an upgrade was made over Win98. So you don't need to worry with it. ;)
     
  15. rattlsnak

    rattlsnak Private E-2

    That is wierd. When I bought it brand new, it had XP Home, but I did upgrade it to XP Pro some time ago. Anyway, thanks for all the help!
    M.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Let me know if you have any other issues with it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds