Stealth MBR rootkit

Discussion in 'Malware Help (A Specialist Will Reply)' started by dianek, Oct 22, 2010.

  1. dianek

    dianek Private E-2

    Started having problems with IE8. Could not open tabs, ie would always freeze up. could not re-start or close windows. had to do a hard close by turning off using power button.
    could not run updates form MS.
    was able to download firefox and that seemed to work okay, however really need to get IE fixed.

    Ran Combofix and all the other scans suggested in the windows xp cleaning thread.
    I'm having trouble uploading my Malware log (which I already had running on my computer and most recent scan did not find anything) and also my SAS log, which I also already had on my computer which only found 2 adware cookies.

    Any help is greatly appreciated

    Here are my logs:
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    What are all those folders in the root of your C drive from Dec 18, 2008?


    Delete the below folder:
    C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\jxpanaosm



    Now download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
    Make sure you reboot immediately after running TDSSkiller if it finds anything.




    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • the log from TDSSkiller
    • the log from MBRcheck
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. dianek

    dianek Private E-2

    Thanks for the reply Chaslang.

    Ran the Tdsskiller program and it did find Rootkit.Win32.Tdss.Tdl4 which I told it to cure.

    I removed the folder you directed me to.

    Here are my logs, however, I am still having the same problems. In fact, I had to to a hard re-start after running Tdsskiller. I still can't get to windows update, it says connection error.

    Again, thanks. Hope we can get this fixed.
     

    Attached Files:

  4. dianek

    dianek Private E-2

    Yipee!!!!

    I was atleast able to update windows in clean boot mode, all except for 3 updates for MS office 2003 (there is a known issue with those).

    So for now at least that problem is solved.
    The tabs in IE8 are also working (for now)

    I'll wait hear from you about my logs.

    Thank you
     
  5. dianek

    dianek Private E-2

    Oops too early to get too excited. When I got back to normal boot mode, still can"t get to windows update. So it appears that there is another problem to contend with in the future. Anyway, I'll still wait to hear from you about my logs.

    Thank you.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You attached the TDSSkiller program instead of the log. Please be more careful. Don't worry about it now since MGtools was able to locate and automatically included the log from TDSSkiller.

    Windows Update issues are quite frequently due to issues with Windows itself. It is not always due to malware. If you can go to Windows Update in safe mode but not in normal mode, it is likely just due to a program you are running in normal mode but not in safe mode. Possibly your protection software especially a firewall. Try shutting down AVG9 and your firewall and see what happens. Also it could be due to a browser addon. Try running IE with no addons.

    Also, some people need to put Microsoft Update into their Trusted Zone and this will sometimes help. It is even a tip the Microsoft suggests.

    You did not answer my question about all those folders?

    Your logs are clean.
     
  7. dianek

    dianek Private E-2

    Thank you for looking at the logs. sorry about not putting the correct log txt in.
    computer does seem to be working much faster. so far no trouble working in IE8.

    In regard to those folders, I honestly don't know why or what they are. Looked at the properties of a few of them and they say they came from another computer and may be blocked to protect our computer.

    Is there any way to find out what they pertain to? I'm wracking my brain to think of what we may have done back in 2008.

    Again, thank you.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Look in some of the folders to see what is in them. Perhaps it will help you figure out what they are. There are folders with the same date referring to GateWay and IBM. Maybe you backed up a bunch of info from other computers in to folders like this. That would not be too good an idea since it it basically impossible to keep track of what they are this way..... as you can now atest to. They could even be related to O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe which is used for online support stuff .
     
  9. dianek

    dianek Private E-2

    thank you. i will do that. since we have had this computer since 2005 (our previous one was a gateway), I honestly don't know what I would have been doing in 2008 to get those folders. is it at all possible they could have come from one of our kids zip drives that they use to take stuff to and from school?

    now, do I need to get rid of any of the programs I used to locate the rootkit? again, thank you very much.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    I doubt it.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds