BleepingComputer.com: Rootkit and hacked windows needs cleaning

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
  • 3 Pages +
  • 1
  • 2
  • 3
  • You cannot start a new topic
  • This topic is locked

Rootkit and hacked windows needs cleaning Have Laptop ready per your instructions.Files inc.

#31 User is offline   boboliman 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 38
  • Joined: 07-December 10
  • Gender:Male
  • Location:Virginia

Posted 09 May 2011 - 09:22 AM

Hi Gringo, I'm still here. Work is hectic, and I have no working computer at home. It is now screwing with certificates, not allowing any secure site access.

Here is the requested scan log.

Thanks...


aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software
Run date: 2009-01-01 00:10:00
-----------------------------
00:10:00.767 OS Version: Windows x64 6.1.7600
00:10:00.767 Number of processors: 2 586 0x2505
00:10:00.767 ComputerName: DEATHSTAR2 UserName: superman
00:10:54.774 Initialize success
00:11:12.761 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
00:11:12.761 Disk 0 Vendor: WDC_WD32 01.0 Size: 305245MB BusType: 3
00:11:12.776 Disk 0 MBR read successfully
00:11:12.776 Disk 0 MBR scan
00:11:12.792 Disk 0 Windows 7 default MBR code
00:11:12.792 Service scanning
00:11:13.806 Disk 0 trace - called modules:
00:11:13.806 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
00:11:13.806 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80045c4740]
00:11:13.822 3 CLASSPNP.SYS[fffff88001b2e43f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa800447e050]
00:11:13.822 Scan finished successfully
00:13:16.547 Disk 0 MBR has been saved successfully to "C:\Users\superman\Desktop\MBR.dat"
00:13:16.563 The log file has been saved successfully to "C:\Users\superman\Desktop\aswMBR.txt"

FIXMBR button is lit, and FIX is grayed out.


boboli

This post has been edited by boboliman: 09 May 2011 - 09:38 AM


#32 User is offline   gringo_pr 

  • Bleepin Gringo
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 85,453
  • Joined: 03-July 08
  • Gender:Male
  • Location:Puerto rico

Posted 09 May 2011 - 11:48 AM

Hello

I know you ran this before but I want you to run it with these instructions and I want you to redownload it - it has been updated

Please download Kaspersky Virus Removal Tool and SAVE it to your desktop

  • Right click and run as admin (xp please double click to run)

  • select lang

  • click on next

  • accept the license aggreement

  • select location and click on next

  • in autoscan make sure the first three boxes are checked and the box next to the C:/ drive

  • click on start scan

  • when complete click on report

  • in the three drop down boxes choose autoscan - do not group and important events

  • click on save and save to desktop

  • copy and paste this report in your next post

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic


Please Only Copy And Paste Reports Into Topic - Do Not Attach

My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->Posted Image<-- Don't worry every little bit helps.

#33 User is offline   boboliman 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 38
  • Joined: 07-December 10
  • Gender:Male
  • Location:Virginia

Posted 10 May 2011 - 02:38 PM

Autoscan: completed <1 minute ago (events: 2, objects: 531143, time: 01:11:59)
1/1/2009 4:26:50 AM Task started
1/1/2009 5:38:49 AM Task completed

#34 User is offline   gringo_pr 

  • Bleepin Gringo
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 85,453
  • Joined: 03-July 08
  • Gender:Male
  • Location:Puerto rico

Posted 11 May 2011 - 02:53 PM

:Run sfc /scannow:

    If you have the win 7 cd please put it in your cd drive.
    • Stop all running programs and make sure you are at a point in time when letting your computer work for a minute isn't going to be a problem.
    • Get Erunt. With this simple utility you can backup your registry before any changes are made and restore to these saved changes should it become necessary.
    • Make a registry backup with Erunt before continuing. You can also create a restore point for added insurance. (Start > All programs > Acessories > System tools > System Restore)
    • Click Start > run > type in sfc /scannow > Press Enter. This is the system file checker. What it does is scour your system and look for windows system files that are corrupt or missing. If it needs a file off of the win 7 cd it can grab it if you have the win 7 CD. If you DON'T have the win 7 cd all is not quite lost yet. We can try restoring system files from your computer's dllcache (which would possibly require a registry change).
    • After this process is complete you may need to reboot.

    Note: If you are a power user using registry tweaks, you will likely have to reapply those tweaks after the scan is complete.

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic


Please Only Copy And Paste Reports Into Topic - Do Not Attach

My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->Posted Image<-- Don't worry every little bit helps.

#35 User is offline   gringo_pr 

  • Bleepin Gringo
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 85,453
  • Joined: 03-July 08
  • Gender:Male
  • Location:Puerto rico

Posted 15 May 2011 - 02:27 AM

Hello

48 Hour bump

It has been more than 48 hours since my last post.

  • do you still need help with this?
  • do you need more time?
  • are you having problems following my instructions?
  • if after 48hrs you have not replied to this thread then it will have to be closed!


Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic


Please Only Copy And Paste Reports Into Topic - Do Not Attach

My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->Posted Image<-- Don't worry every little bit helps.

#36 User is offline   boboliman 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 38
  • Joined: 07-December 10
  • Gender:Male
  • Location:Virginia

Posted 15 May 2011 - 10:23 PM

Hi Gringo,

I did as you instructed and the scan turned up clean. One thing I noted was as the scan was running, a little over 800 files were created in c:\windows\winsxs\temp.

#37 User is offline   gringo_pr 

  • Bleepin Gringo
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 85,453
  • Joined: 03-July 08
  • Gender:Male
  • Location:Puerto rico

Posted 16 May 2011 - 02:41 PM

Hello

I don't know what else to do - I don't see anything that would cause your problems and I have thrown everything I can think of at it



gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic


Please Only Copy And Paste Reports Into Topic - Do Not Attach

My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->Posted Image<-- Don't worry every little bit helps.

Share this topic:


  • 3 Pages +
  • 1
  • 2
  • 3
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users