Invisble IE running, bootkit log.

Discussion in 'Malware Help (A Specialist Will Reply)' started by MatthewToads, Jul 28, 2010.

  1. MatthewToads

    MatthewToads Private E-2

    (sorry if this is a double thread, not sure if it went through the first time I posted it.)

    Just like everyone else, this new IE virus that none of the big free programs like MBAM and AVG have gotten a hold of yet.
    Ive looked in the task manager to confirm that explorer.exe is running, even though I dont use it.

    Just hoping Im starting off right, and can get help with what to do next.
    Halp!, please and thank you. :)

    I got bootkit remover, and here is the log.

    System volume is \\.\C:
    \\.\C: -> \\.\PhysicalDrive0 at offset 0x00000000'00007e00
    Boot sector MD5 is: d8bab45f7abdaa4dd5fdd1f3fbc83aba

    Size Device Name MBR Status
    --------------------------------------
    37 GB \\.\PhysicalDrive0 Unknown boot code

    Unknown boot code has been found on some of your physical disks.
    To inspect the boot code manually, dump the master boot sector:
    remover.exe dump <device_name> [output_file]
    To disinfect the master boot sector, use the following command:
    remover.exe fix <device_name>


    Done;
    Press any key to quit...
     
    Last edited: Jul 28, 2010
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!



    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
    Now run MGtools per the below instructions and attach the requested MGlogs.zip file


    Also address the below Warning/Questions?

    WARNING: Do you have all important data backed up? You really should do this before continuing on to the next steps I will be posting after I see the above log since we will need to rewrite your MBR to fix this and while most times this can be done without any problem, these infections can react badly and that could result in a PC not being bootable. You really don't have much choice though since these infections are too dangerous to your security to leave on a PC.


    Also note if you have a Dell PC which uses a non-standard MBR ( or another manufacturer's who does similar to Dell) , fixing the mbr may prevent access the the Dell Restore Utility, which allows you to press a key on startup and revert your computer to a factory delivered state. There are a couple of known fixes for said condition, though the methods are somewhat advanced. If you are unwilling to take such a risk, you should not continue but you risk serious problems leaving this infection in place and thus your only other option would be to try using the Dell Restore Utility to return a factory ship state which will remove everything you additional you have put onto the PC.
     
  3. MatthewToads

    MatthewToads Private E-2

    Thanks for your time.
    Here are those two attachments.

    Yes, I have a backup restore point that is not disabled from this virus.

    I am not 100% sure what this means, but I dont think my dell runs a non-standard MRB.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not sure what you mean by "restore point" if you are really referring to Windows System Restore, that is not a backup and you need to back up your own important data properly. System Restore does not do this.

    Most Dells do! ;)
     
  5. MatthewToads

    MatthewToads Private E-2

    I have both a backup and a restore point, sorry for that confusion.

    and how can I be sure about the MBR?

    also, a moment ago a program, probably one I just got from that link you gave me, started using every bit of memory I have available, locking me up for about 10 minutes and then closing due to an error. I had just under 1GB memory available.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I cannot comment since you did not say what program you are talking about.




    Now if you wish to continue and fix the malware - please do the following:
    • Run MBRCheck.exe
    • Wait until you see the following lines:
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
      • Options:
        [1] Dump the MBR of a physical disk to file.
        [2] Restore the MBR of a physical disk with a standard boot code.
        [3] Exit.
        Enter your choice:
    • Please push the 'Y' key and then press Enter
    • When the program asks you to Enter your choice: enter 2 to Rstore the MBR and press the Enter key
    • Now the program will ask you to "Enter the physical disk number to fix (0-99, -1 to cancel):"
      • Enter 0 and press the Enter key.
    • The program will show Available MBR codes as below
    • You need to select your version of Windows frrom the list. For example, enter 0 or 1 for XP or enter 3 for Vista.....etc. and then press Enter.
    • The program will prompt for confirmation. Type 'YES' and hit Enter.
    • Left click on the title bar (where program name and path is written). From menu chose Edit -> Select All
    • You will see all the text in the window get highlighted.
    • Hit the Enter key on your keyboard to copy all of the text into the clipboard.
    • Paste that text into Notepad, save it to your desktop as MBRfix.txt
    • Restart your PC.
    • Attach the MBRfix.txt file to your next message..
    Then since you have a second physical drive you need to repeat the above but replace the
    • Enter 0 and press the Enter key.
    With the below for the second drive
    • Enter 1 and press the Enter key.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds