My wife has this virus on her Dell Vostro 410 PC. From what I can gather off the web it hides in the MBR and reinfects the machine on every boot even after rootkit cleaners have erased it from the OS.
I have tried Kaspersy's TDSSKiller, and although it appears to have killed the OS rootkit with a tweak (renamed the file before running it), on reboot it's still in the MBR. And we are still getting redirects.
None of the tools I've been trying will function. Gner, unhackme, prevxcsi etc. wont run - they either freeze or shut down. I haven't tried Combofix yet but I don't expect I'll fare any better with that and I wouldn't know how to use it anyway without help. Kaspersy's online scanner freezes on the page as do all other Kaspersy pages (I managed to download TDSSkiller by downloading it to my machine and transferring it using a pendrive).
One fix appears to be replacing the MBR with a copy through the recovery console using the fixmbr tool. However, Dell PCs use a proprietary MBR and replacing it in this way will bugger up the partitions, see here:
I need help with this and if possible a copy of a Dell MBR. Apparently it doesn't matter which Dell model it comes from. The site above explains it in more detail.
Hitting F12 at boot gives me the following information:
HARD DISK
- SATA-0 Hitachihi HDP725050GLA36
- BOOTABLE ADD-IN CARDS
CDROM
UTILITY PARTITION
I tried Dell telephone support (we still have support until 2012, but only hardware, it seems, so no help there except a remote reinstall for a fee. I'm hoping to avoid that).
I've been at this for a days now and am exhausted looking for a fix.
Yep this is a real nasty piece of work, it does bring in a considerable amount of malware. Delete the re-named version of CF from the Desktop. Reboot into Safemode with Networking.
To do this, re-boot and continuously tap the F8 key until you see the Advanced Windows menu screen. You will see several options, select Safe mode with networking. Follow the prompts, when you have a stable Desktop download Combofix from any of the following links:
Don`t forget Combofix must be saved to your desktop. <--Very important
Ensure you have disabled your Firewall and all anti virus and anti malware programs so they do not interfere with the running of ComboFix. <---Very important
Please include the C:\ComboFix.txt in your next reply for further review.
Examples of how to disable realtime protection available at the following link :-
Note: Do not click combofix's window with your mouse while it's running. That action may cause it to stall.
*EXTRA NOTES*
If Combofix detects any Rootkit/Bootkit activity on your system it will give a warning and prompt for a reboot, you must allow it to do so.
If Combofix reboot's due to a rootkit, the screen may stay black for several minutes on reboot, this is normal
If after running Combofix you receive any type of warning message about registry key's being listed for deletion when trying to open certain items, reboot the system and this will fix the issue (Those items will not be deleted)
Be aware, because you are running in Safe mode if CF forces a re-boot you must be there to tap F8 key to get into Safe mode again, bit of a pain but necessary.
I booted into safe mode and Combofix started up immediately, ran and produced the report below. I let it run even though it's not a new downloaded copy as you instructed. Should I start over and run a completely new copy or is this one OK?
Tony
ComboFix 10-09-30.05 - Administrator 01/10/2010 22:09:11.1.4 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2573 [GMT 1:00] Running from: c:\documents and settings\Administrator\Desktop\zfh.exe AV: McAfee Anti-Virus and Anti-Spyware *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} .
((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) .
c:\documents and settings\Administrator\Application Data\Idan c:\documents and settings\Administrator\Application Data\Idan\mokul.exe c:\documents and settings\Administrator\Application Data\Ynylet c:\documents and settings\Administrator\Application Data\Ynylet\xafo.exe c:\documents and settings\Administrator\GoToAssistDownloadHelper.exe C:\Thumbs.db c:\windows\run.log c:\windows\system32\sfcfiles.dat
. ((((((((((((((((((((((((( Files Created from 2010-09-02 to 2010-10-02 ))))))))))))))))))))))))))))))) .
No need to do CF a re-run at present, As follows please :-
Step 1
Run an online virus scan with
Kaspersky from
HERE. Use Internet Explorer to get there. This scan is very thorough and may take several hours to run, please allow it to complete.
1. At the main page. Press on "
Accept". After reading the contents.
2. At the next window Select Update. Allow the Database to update.
Note: If prompted to run or update your Java, then follow the prompts to do so. Kaspersky requires Java to run.
3. Once the Database has finished, under the
Scan icon Select
My Computer to start the scan.
4. Select
Scan Report.
5. If any threats were found they will appear in the report
6. Select "Save error report as"
Then in the file name just type in kaspersky
Under "save as type" select
text .txt Save it to your Desktop.
Copy and post the results of the Kaspersky Online scan. If no threats were found then report that as well.
Download Security Check by screen317 from
HERE or
HERE.
Save it to your Desktop.
Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box. Press any key when asked.
A Notepad document should open automatically called checkup.txt; please post the contents of that document.
Post the logs from Kaspersky and Security Checks, also system update, improvements? issues?
Kaspersky online scan is very thorough and can take a considerable time to complete. I prefer it because it only identifies and doesn`t fix issues, that allows us to decide if an item is really malicious.Only one item to deal with from the log, the rest will go with our clean up procedure.
Copy the text between the dotted lines below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy): ------------------------------------------------------------------- :Processes
:Files C:\Tony\DVD region free stuff\DVD region killer v2.7.0.2.exe ipconfig /flushdns /c :Commands [CreateRestorePoint] [EmptyFlash] [EmptyTemp] [Purity] [ResetHosts] [Reboot]
Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
Click the red Moveit! button.
Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
Close OTM
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
If the machine reboots, the Results log can be found here:
c:\_OTMoveIt\MovedFiles\mmddyyyy_hhmmss.log
Where mmddyyyy_hhmmss is the date of the tool run.
Step 2
Uninstall the following from Add/Remove Programs via the Control Panel
Java(TM) 6 Update 5 Java(TM) 6 Update 7 Adobe Reader 8.1.2 } If you need this version of Adobe reader do not uninstall Adobe Reader 8.1.2 Security Update 1 (KB403742)
Step 3
Your Adobe Acrobat Reader is out of date. Older versions are vulnerable to attack.
Please go to the link below to update.
Adobe Reader Untick the Free McAfee® Security Scan Plus (optional) unless you want it.
Post log from OTM, also system review, improvements? issues?
I'm going to delete Adobe Acrobat and replace it with Foxit. I've got Foxit on my PC and it's way faster.
Regarding the "C:\Tony\DVD region free stuff\DVD region killer v2.7.0.2.exe" you are looking at. I downloaded it years ago but never ran it. The DVD in our living room is multiregion so we never bothered.I really should have deleted it, which I'm happy to do now. Do you want me to still proceed with OTM?
Just a quick system update, which I forgot to include in the last post:
PC shut down and started up normally for a change, - could be a lucky one off - but Kaspersky's TDSSKiller still finds the rootkit in the MBA. Also, still getting google redirects. McAffee update seems to work, although if it is - how come it's not finding anything on its scans?. Attempts to get to windows update fail - connection closed by remote server or can't open the page depending on which browser you use.
Few of other issues that may, or may not be related:
Message window on windows start about Sony Ericsson suite failing to initialize.
Just before windows starts to boot a light blue screen flashes past with "regrun greatis antirootkit" splashed across the screen. It's been there before but has always flashed past too quick for me to see what it was saying. This time it was slow enough for me to catch some of it.
There were no programs propagating in the "add/remove programs" window. I brought them back with REGSVR32 APPWIZ.CPL. Had this earlier in the week when I tried to remove some of those applications I had tried over the last week to clean up the infection. Ran REGSVR32 APPWIZ.CPL to get them back but something hid them again. I think the "regrun greatis antirootkit" message may be a leftover from one of the applications I had to try and remove manually then.
Hiya Tony dont run anything for now, I need to go back over your thread. I did see something related to to a registry program, but thought it was something you had installed. Uninstall the old Java and Adobe entries also delete that DVD file, it is infected.
There are some remnants on your system from Registry protection program, it is possible that when TDSSKiller removes the infection it actually comes back on re-boot. OK lets try a fix.
Proceed as follows :-
Step 1
Download ERUNT(ERUNT (Emergency Recovery Utility NT) is a free program that allows you to keep a complete backup of your registry and restore it when needed.)
Install ERUNT by following the prompts(use the default install settings but say no to the portion that asks you to add ERUNT to the start-up folder, if you like you can enable this option later)
Start ERUNT(either by double clicking on the desktop icon or choosing to start the program at the end of the setup)
Choose a location for the backup(the default location is C:\WINDOWS\ERDNT which is acceptable).
Make sure that at least the first two check boxes are ticked
Press OK
Press YES to create the folder.
Step 2
1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
3. Open notepad and copy/paste the text in between the dotted lines below into it:
Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
If an infected file is detected, the default action will be Cure, click on Continue.
If a suspicious file is detected, the default action will be Skip, click on Continue.
It may ask you to reboot the computer to complete the process. Click on Reboot Now.
If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
Double Click mbam-setup.exe to install the application.
Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select "Perform Quick Scan", then click Scan.
The scan may take some time to finish,so please be patient.
When the scan is complete, click OK, then Show Results to view the results.
Make sure that everything is checked, and click Remove Selected.
When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
Please save the log to a location you will remember.
The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Copy and paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
kevinf80_1d0ac6
2 Intern
•
1131 Posts
807
0
Posted October 1st, 2010 16:00
Hi Tony,
Yep this is a real nasty piece of work, it does bring in a considerable amount of malware. Delete the re-named version of CF from the Desktop. Reboot into Safemode with Networking.
To do this, re-boot and continuously tap the F8 key until you see the Advanced Windows menu screen. You will see several options, select Safe mode with networking. Follow the prompts, when you have a stable Desktop download Combofix from any of the following links:
Link 1
Link 2
Don`t forget Combofix must be saved to your desktop. <--Very important
Ensure you have disabled your Firewall and all anti virus and anti malware programs so they do not interfere with the running of ComboFix. <---Very important
Please include the C:\ComboFix.txt in your next reply for further review.
Examples of how to disable realtime protection available at the following link :-
Disable realtime protection
Note: Do not click combofix's window with your mouse while it's running. That action may cause it to stall.
*EXTRA NOTES*
Be aware, because you are running in Safe mode if CF forces a re-boot you must be there to tap F8 key to get into Safe mode again, bit of a pain but necessary.
Post the log in your reply
Kevin
Kevin