mbr rootkit, need some advice please

Discussion in 'Malware Help (A Specialist Will Reply)' started by lojo, Jan 27, 2010.

  1. lojo

    lojo Private E-2

    I've read the 'read and run first' section and am up to the cleaning for xp 32 bit. I just want to make sure that I should carry on that path at this point.

    Any help would be greatly appreciated! Can anyone hold my hand through this?
     
  2. lojo

    lojo Private E-2

    Sorry, not meaning to bump but couldn't find an edit button. I'ce attqched the gmer.log from before.

    Have downloaded all the programs suggested and am installing and running since no one jumped in and said.. NO, you have and mbr rootkit trojan, that won't work! So I am proceeding.

    I could really use some help here and would be quite grateful.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    We work oldest to newest thread, which is why no one "jumped" into this thread until now.

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.

    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.


    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this aother user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:

    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  4. lojo

    lojo Private E-2

    logs attached

    Here are the logs.. thank you!

    I'm not sure if I still have a problem as the instructions told me to only run each test once. The firewall doesn't come down for a minute on restart now though :)

    There was a problem with MGtools I'll note in next post.

    I did run rootrepeal several times as the log file didn't contain any info as in x# hidden files found
     

    Attached Files:

  5. lojo

    lojo Private E-2

    MGtools seemed to have failed but a zip file was created. Attaching a screenshot of the failure.
     

    Attached Files:

  6. lojo

    lojo Private E-2

    Still have problems it seems:

     

    Attached Files:

    • mbr.log
      File size:
      324 bytes
      Views:
      2
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are getting a false positive from GMER. I am not seeing any evidence of a MBR infection. If you are still uncertain, then just boot to the recovery console and run the command:
    fixmbr

    You need to double the amount of RAM you have:
    Total Physical Memory 512.00 MB
    Available Physical Memory 198.31 MB

    You need to go to the control panel / user accounts and disable the HelpAssistant account!

    Your logs are clean, thought we can remove some junk:
    What is this --> C:\trojan ??

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  8. lojo

    lojo Private E-2

    Thank you. I will do all you have suggested.

    I don't see the help assistant account enabled :confused attached screeny.

    The latest GMER log listed the same address (?) of the rootkit as the first but yes, there are a couple of lines missing compared to my first post in this thread. I will defer to your wisdom and experience.

    lol, the C:\trojan is a folder I made to save tings in related to this problem, it includes some of the programs from 'reads and run' I will move them and delete folder.

    Thanks a million! Will do as directed.
     

    Attached Files:

  9. lojo

    lojo Private E-2

    Succesfully fixME.reg

    Combofix warning attached.. won't go further without advice.

    oops, it said combofix uninstalled.. panic mode? Will still await instructions
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What issues are you having?
     
  11. lojo

    lojo Private E-2

    Just being super careful I guess... the warning from combofix said I may have a file patching virus, 'Virut'. It could be insignificant or a false positive? I just don't want to make any blunders.
    Do you suggest I move forward with your previous instructions?
     
  12. lojo

    lojo Private E-2

    reinfected on reboot after toggle system restore?

    Okay, I followed existing instructions when I turned off computer after disbling system restore I got a cpl of messages on shut down. One was something like dwwin.exe is not responding... or was it dde.win? something about each of them.

    I restarted and went to properties, checked the turn on system restore box and moved the slider to 6% from 12%.

    Windows firewall was red and said something about a firewall being down... this is what was happening before.

    Should I start over or..?

    I will follow all dorections meticulously.

    Thnak you for all of your help!
     
  13. lojo

    lojo Private E-2

    Toggled system restore as last step and when I rebooted (as noted last post) the firewal went down for about a minute then back on. This is what alerted me to the problem in the first place a few days ago.

    So I went through the process again paying particular attention to detail.
    I still got the
    error so installed .net framework so we can retry if needed?

    Logs attached

    Thank you for your patience and help!
     

    Attached Files:

  14. lojo

    lojo Private E-2

    last logs

    SAS and Mbytes showed no results but here are the files.

    Thank you!

    Edit: Somehow the post with MGzip,combofix, and rootrepeal was sent to moderator queue for approval, please advise if I should post it again.
     

    Attached Files:

  15. lojo

    lojo Private E-2

    email headers, may be hijacked?

    I got a mailerdaemon return that looks like I may be spamming due to this trojan
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. I would suggest that you post in the software forum for assistance with the Process .dll.

    Malware can be in your Yahoo mail account and the only thing you can do is to delete all suspect emails. Then use a different computer to change your password in Yahoo.
     
  17. lojo

    lojo Private E-2

    Thank you for all of your help. The process dll will not appear after I run the tests again as I have now installed the microsoft .net framework. The page that instructed me on that error says that sometimes critical information will be missing if all of the MG tools don't run, (because of that error) so I would like to beg your indulgence, at your leasure, to review my logs again after I go through the steps one more time with all of your tools working.
    I am convinced that I am still infected for two reasons: On startup my firewall goes down for a short while... And when I type in a browser log box many times the letters are not registered on the page. I believe I have a very stealth resident key logger. Please indulge me, it may help someone else down the line.

    I will change my yahoo password to a random string and not access that account again to eliminate that possibility.

    Thank you for your patience, I still have a problem here and fdisk isn't a great option at the moment
     
    Last edited: Jan 31, 2010
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I will recheck your logs as soon as you can get them attached.

    Have you tried doing any online scans?

    Please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. It does not save a log.
    After running this and assuming it runs, then you can run other tools.
     
  19. lojo

    lojo Private E-2

    Thanks Tim,
    I ran the online scan and it didn't find anything.

    I ran the gamut again today and am attaching logs. I haven't rebooted to see if the firewall is delayed in case that is a pint of reinfection.

    Changes I've made:
    In Windows firewall settings I disabled:
    • Services 65533 TCP, 52344, 3246, 2479 I have no idea what these are.
    • File and print sharing
    • Itunes
    • yahoo messenger
    • all online accesses for hp printer software I installed recently from the hp website with a photosmart c4480 printer.
    ++++++++++++

    I haven't changed my yahoo password but I did delete ALL messages sent and received. I got another mailer demon notice today.

    May be totally unrelated but someone tried to hack (failed 5 times so I got notification) into one of my forum accounts yesterday and the ip it came from was from 209.200.185.181 who seem to be an internet security firm dealing with DDoS attacks:confused

    +++++++++++

    I'll not reboot until you've had a chance to take a look at the logs and give me the go ahead.

    Thanks again so much for your help, you've been very kind and patient.

    Logs attached. SAS found no results, so didn't log.
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The HelpAssistant user profile is still showing as not disabled. Have you tried to do so?

    You may need to save your contact info, then delete your email account and create a new one. ( Again, using a different computer).

    Do this:

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
    C:\10.1.19.109
    C:\Documents and Settings\Administrator\Local Settings\temp\tmp28f.tmp
    
    Folder::
    C:\Documents and Settings\HelpAssistant
    C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
    C:\10.1.19.109
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  21. lojo

    lojo Private E-2

    final (?) logs attached

    Thank you, Tim.
    Logs attached.

    When I rebooted the firewall didn't go down. When I log into a site and enter password there is no lag and no groups of missing letters.



    Help assist: I may not be getting how to do this as when I go to Control Panel User Profiles all I see is admin and 'Guest' guest account turned off as per the screenshot attachment in my post #8 here. I must be misunderstanding something?

    email: I will not log into that account again from here but go to another computer, export contacts then create new account.

    Please let me know if my logs look clean, I will check back tomorrow.

    Thanks again for all of your help!
     

    Attached Files:

  22. lojo

    lojo Private E-2

    update

    I haven't logged into that email account (yahoo) since running combofix. This is the second or third reboot since then. My firewall went down again. It stays down for less than a minute I would guess. I can time it if it matters.

    I don't have any other firewalls running that would trump windows firewall.

    If you are seeing something in the logs in re HelpAssistant that I can't see (pls see my attchmnt in post #8) it might only be letting me see what it wants to?
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to right click on My Computer / properties / and the last tab (?) make sure that Remote Assistance is not checked.

    Windows firewall is worthless, you should download and install one of those suggested here:
    How to Protect yourself from malware!

    Otherwise, I am not seeing any issues in your system.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to tahe cleaning procedures ian step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  24. lojo

    lojo Private E-2

    Thanks so much for your help Tim.

    It wasn't even showing in the window attached. It did show per your last instructions! So I disabled it.

    I will replace my windows firewall and assume that all is well now.

    But there is/was something 'telling' my firewall to sometimes (only after two or three reboots since running your tools and then consistently) go down on reboot? I won't tax your patience any longer if the new firewall behaves properly, and I thank you immensely for all your help. Of course when I am able I will purchase programs through your links.

    Best Regards
     

    Attached Files:

  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome.....but there is no need to purchase anything. My link on how to protect yourself should have plenty of freeware choices.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds