MBR Rootkit Detected

Discussion in 'Malware Help (A Specialist Will Reply)' started by theaftermath06, Nov 17, 2010.

  1. theaftermath06

    theaftermath06 Private E-2

    Hello and thank you first of all for these forums!

    I noticed that my computer was acting odd and slow and ran SAS and it found a trojan. When I tried to reboot it froze at the "Windows is Shutting Down" screen so I had to hard boot it. I have ran all of the programs and tests except for Combofix as I was unable to uninstall Online Armour. When I tried it said "Access Denied..." I would think that Online Armour is hooked at this point. Something that I noticed before I knew I was infected was on my Ubee Modem D3.0 my DS light turned orange from green and my ethnet light began flashing (it used to be solid). Within a week of this I could not get online anymore.

    After the Charter subcontracted tech came out and got me back online the DS and ethnet lights were still the same (orange, blinking). He said he was not sure why the DS was orange and why the ethnet was blinking. I Googled the DS light issue and found a post that said it was the modem bonding channels.

    Anyways here are the logs requested... What a nightmare this is! I will only say thank you to anyone that can help...

    PS. The only thing I have done before I noticed the problems is using a website called autohits.dk. It is a site that autosurfs for me to earn credits that goes towards my page being viewed by others. I am not saying for sure that this is where the malware came from but Malwarebytes blocks IPs constantly from this autosurfer (I got the paid version of MBAM after I noticed the problem and have since stopped using this site).
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. What detected a rootkit? Did it give an exact path to the file?
     
  3. theaftermath06

    theaftermath06 Private E-2

    Hi Tim and thank you for helping me.

    SAS detected it. It is in the log and it does show a path.

    rrlog also shows the rootkit and path.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What is your G:\ drive? Is it a partition or an external drive? Is it bootable?
     
  5. theaftermath06

    theaftermath06 Private E-2

    It is my external drive, WD 500GB Book Essentials I believe. It just powers when a file is accessed. I can tell just by the performance that something is on there. I can not safely shut the drive down now. I have to unplug it when the whole desktop is off. Even when I unplugged the drive, I still couldn't uninstall Online Armour and had very limited access to any of the files that RootRepeal found hooked from a scan yesterday. There was probably 20 NT files that were hooked. I'm not sure exactly how everything works but I would think that the trojan has spread after seeing the performance and reports of hooked files after I unplugged the drive and started up the computer.

    Update: I did successfully safely remove hardware (G:/ drive), this was the first time I tried since I ran MG Tools.
     
    Last edited: Nov 17, 2010
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I assume that is not a bootable drive, so there is no MBR. The scans don't know that. ;)
     
  7. theaftermath06

    theaftermath06 Private E-2

    Thanks Tim for looking over my logs. Why does RootRepeal show files that are still hooked? I will go through and clean up everything but something seems to still be wrong. I can now disable and delete Online Armour now anyways :-D
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What is happening that makes you think something is still wrong? Would you like to do an online scan?

    eSet Online Scan.
     
  9. theaftermath06

    theaftermath06 Private E-2

    Hi Tim, well I found a few things out today. I installed Comodo Firewall and Antivirus and it found 8 infections!

    First of all I have set everything at max protection and the scanner on high huer. sensitivity. 6 of those 8 were false positives.

    6 found to be false -
    combofix.exe - I had this on both my boot and external drives.
    mbr.cfxxe
    mbr.exe
    mgtools - This was on both boot and external drive also

    I had some of these on both drives just in case the file had to ran on the actual drive since I couldn't select the drive it scanned. :confused

    Now the two that Comodo AntiVirus DID find

    couponprinter.exe - I wasn't really sure if this was also a false positive or not so I quarantined it anyways. I Googled it and found mixed reviews. The one I went with was MBAM saying it had trojan buried. That with Comodo finding it... yea your gone!

    sysimx.dll.exe - This is reported as a trojan/virus that allows remote users to get sensitive info and is rated a 5 I believe.



    The crazy thing is I have ran ESET Online Scanner, Prevx 3.0 (this was the free version so it only detected problems and then corrected certain ones but this file was not detected), Microsoft Security Essentials, MBAM, SAS, Rootrepeal, TDDS Root Removal, Blacklight and Blacklight Online Scanner, MGTools (Which I'm not sure if this is supposed to find roots like that).

    I gotta say that I am going to be running Comodo AV right along with MSSE from now on. I am floored that all of the other ones missed that!

    Anyways, the reason I think something is still wrong is because I have a file that I am unable to remove from recycle bin. Sometimes when I right click on an item it takes over 10 seconds for the options for that file to show up. When I click on drives (C:/ or G:/ which is my external portable) it shows the flashlight searching for about 5-10 seconds too. Firefox takes over 10 seconds to start and then another 5 - 10 to load the page (yahoo.com).

    Now this is not every single time but more times than not it does hang like that. I haven't defragmentted yet but I just did that shortly after I thought there were problems.

    The folder that will not delete is f9e8f19e5fd9601e4a32, which was on my external drive. It was right in the root of the drive and I have no idea what it is/was and have no idea how it got there. There was 4 of them and I deleted them after I seen MBR Detected in RootRepeal from the first scan.

    The odd thing is when I open my Recycle bin I do not see anything in there. It shows that it is empty but when I empty it, it says "Cannot remove folder...:Access is denied". I have checked the view options to make sure nothing that shouldn't be checked is not and vice versa.

    I guess from here I will wait to here back from you if you have any suggestions and then defrag and memory dump and try to find a good optimize program. Maybe some settings have changed or something. I don't know but things still seem very slow compared to what they used to be.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you tried any other removal tool such as CCleaner or Your uninstaller or File Assassin?

    What all is on your G:\ drive? Can you save the info / data on that drive and do a reformat?

    Let's take a new look at your logs, so run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip
     
  11. theaftermath06

    theaftermath06 Private E-2

    Hi Tim,

    I did run all 3 of those on the file. When FA tried to delete it, It said that it was removed successfully but it is still there every time. CCCleaner says 2 files cleaned but file(s) remain, Uninstaller says it is explorer.exe and can not delete or uninstall it.

    I have quite a bit of music and pictures stored on that drive. Do you think it would be safe to just move all of that to my C:/ drive, reformat, and then move the files back?

    Also do you think it would be better to run all of those scans again while those files are temporarily on my C:/ drive? If you don't mind me asking, what would be the best way to reformat that external portable drive?

    Here is the logs you requested too.

    Oh yea I did defrag too and still very slow with performance. I even disabled my MBAM protection module for now to see if things speed up a bit. I have used Win Utilities to correct errors with my Registry too. I have used that for probably 2 years at least now and never a problem so I keep using it. It did find a lot of errors (I would imagine from all of the uninstalling I have been doing) but my computer is still very slow for some reason.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any issues in those logs. Have you plugged in your external drive and done a deep scan with MBAM? If it all comes out clean, then you could transfer your files back to the c:\ drive and format the external. It is usually just a matter of opening My Computer and right clicking the external drive and choosing to format it.
     
  13. theaftermath06

    theaftermath06 Private E-2

    Something else I thought you should know is that I now have System Volume Folder and Recycler folders on my external drive. I never had these on here before and maybe this is why my computer is slower then usual. My computer has to access that System Volume info all of the time???
     
  14. theaftermath06

    theaftermath06 Private E-2

    Hey Tim, just wanted to give you an update. I reformatted the external drive. I opened it up and that System Volume Information folder is still there. I tried to run the File Assassin on it and it looks like it did take care of the file that was in there (Mountain Remote Desktop Support or something like that) and soon as I did that the Recycler folder is back (S-1-5-21-1644491937-1844823847-725345543-1003) with 2 files in it (desktop.ini and INFO2). I can delete desktop with FA but whenever I try with FA on INFO2 it deletes it but adds 2 or 3 files after (DG17.ini, DG18, DG19).

    I never used to have System Volume on this external or Recycler, or at least I never seen them before. I'm at a loss of options here...
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go to the control panel, click on folders and then the view tab and see if Show Hidden files is still ticked. If it is, untick it and then see if the files still show on the external drive.
     
  16. theaftermath06

    theaftermath06 Private E-2

    Hey Tim, I know it is ticked still to show hidden files. I will change that then. I didn't know or think that those two folders would be on the external... Shows how much I know... :-o
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  18. theaftermath06

    theaftermath06 Private E-2

    Alright Tim, Thank you so much for spending your time with me...

    Thank you again! :wave
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     
  20. theaftermath06

    theaftermath06 Private E-2

    Hi Tim, It's me again :confused

    You had said that my external didn't have a MBR Rootkit because it didn't have a MBR. I was still looking over things because still slow and my external drives green light is always on now (has been since the problem started), where it would only come on before when I accessed a file from it or added a file to it. Anyways I did find this info and was looking to see what you thought.

    I attached a screenshot of what I was talking about.

    I imagine you are tired of helping me but I am at my wits end man...
     

    Attached Files:

  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have your external drive plugged in and do the following:

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...

    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.
     
  22. theaftermath06

    theaftermath06 Private E-2

    Hi Tim, Here is the log you requested.
     

    Attached Files:

  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This shows that you are fine:
    Code:
          Size  Device Name          MBR Status
      --------------------------------------------
        298 GB  \\.\PhysicalDrive0   Windows XP MBR code detected
                SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
        465 GB  \\.\PhysicalDrive1   RE: Western Digital MBR code detected
                SHA1: CCCF1B32EE08ECFB66B30883CFF6110F69219FEA
     
  24. theaftermath06

    theaftermath06 Private E-2

    Ok, Thanks again Tim for all of your help and patience! It is very much appreciated! :cool
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are quite welcome. Safe surfing! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds