MBR virus/rootkit and IE redirection/spoofing

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by r40, Jun 28, 2011.

  1. r40

    r40 Private E-2

    Hi, and thanks in advance.

    Symptoms:
    1) Recently, Verified by Visa applets on numerous commercial websites have been being spoofed and redirected within IE, requesting personal data (bank account/card numbers/PINs/etc etc). A user of the system unfortunately provided this information, and realizing the mistake has already completed work with the institution in question to reset and re-secure all accounts. From my limited research, the closest threat I could find matching the symptoms was backdoor.maosboot.

    2) Generalized extreme lack of responsiveness of system, has gotten worse over time. CPU and memory do not appear to be bottlenecks. System had previously performed without significant performance problems. Unfortunately, this is a relative's system and I have little insight as to what was changed over the last year.


    I have read through and followed all requested steps in the pre-req post, and will attach the requested logs. Several items of note turn up in rootrepeal's files, drivers, and stealth objects reports, including a potential MBR infection. I am reasonably computer literate, but would appreciate a hand from a more trained eye with a thorough removal effort.

    Thanks again!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. r40

    r40 Private E-2

    Remaining logs attached. I have provided two additional RR logs which seemed noteworthy, feel free to disregard if not relevant.

    Note: MGtools did raise a 16 bit dos error (Error #3 from the instructions on using MGtools). However, running the provided procedure to correct the problem (recreation of the VDD reg key) was not effective. If the error is ignored, MGtools continues to run and continues to raise the error. I've attached the resulting log, which was generated despite the error.

    Exact MGtools error follows:
    C:\WINNT\system32\cmd.exe
    NTVDM has encountered a System Error
    NTVDM has encountered a System Error c0h Choose 'Close' to terminate the application.
    (Close) (Ignore)
     

    Attached Files:

  4. r40

    r40 Private E-2

    Took me a few minutes to post the remaining logs, sorry about that. You're too quick :)

    Ran TDSSkiller, detected threat Backdoor.Win32.Sinowal.knf.

    Shall I proceed with curing/quarantining?
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you need to select cure and reboot. Then attach the log to your next reply.
     
  6. r40

    r40 Private E-2

    Cured and rebooted. TDSS log attached.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Use windows explorer to find and delete:
    C:\WINNT\Temp\51e158c6
    C:\WINNT\Temp\b7b34acb
    C:\WINNT\Temp\d78b39e2

    Now let's make sure the MBR is ok:
    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...

    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.


    Also tell me how things are working now.
     
  8. r40

    r40 Private E-2

    Files deleted. Running MBRcheck and will advise


    C:\>for /f %a in (a.txt) do del %a

    C:\>del C:\WINNT\Temp\51e158c6

    C:\>del C:\WINNT\Temp\b7b34acb

    C:\>del C:\WINNT\Temp\d78b39e2
    Could Not Find C:\WINNT\Temp\d78b39e2

    C:\>attrib C:\WINNT\Temp\d78b39e2
    A SH C:\WINNT\Temp\d78b39e2

    C:\>attrib -s -h C:\WINNT\Temp\d78b39e2

    C:\>del C:\WINNT\Temp\d78b39e2

    C:\>
     
  9. r40

    r40 Private E-2

    MBRcheck output (.out.txt) and log attached.

    Performance issues seem improved, have not validated the spoofing and redirection issues yet.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Both your MBR's are showing properly. Let me know if you are still having issues. ;)
     
  11. r40

    r40 Private E-2

    All symptoms are gone, you may close this thread at your convenience.

    I really appreciate the help, didn't expect it to be that quick.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  13. r40

    r40 Private E-2

    I think the only items that we installed were SAS, MBAM, and Combofix. I have uninstalled Combofix as above and we'll be keeping the other two to scan regularly.

    I have also passed on the good advice about avoiding infection. Thanks again.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds