BleepingComputer.com: Bowser Redirect Malware/Virus (Rootkit?)

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
  • 5 Pages +
  • « First
  • 3
  • 4
  • 5
  • You cannot start a new topic
  • This topic is locked

Bowser Redirect Malware/Virus (Rootkit?) Do not know how to remove it

#61 User is offline   RPMcMurphy 

  • Bleeping *^#@%~
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 2,397
  • Joined: 16-May 10
  • Gender:Male

Posted 21 August 2011 - 09:38 PM

Chatt:

Try running this again - be careful, the instructions are different this time:

Posted Image Please download Junction.zip and save it to your desktop.
  • Unzip it and put junction.exe in the Windows directory (C:\Windows).
  • Now go to Start > Run to open a run box > Copy and paste the following command in the open run box and click OK:

    cmd /c junction -s c:\ >log.txt&log.txt& del log.txt

  • A command window will open and the system will be scanned.
  • Wait until a log file opens.
  • Copy and paste or attach the content of it in your next reply

This post has been edited by RPMcMurphy: 21 August 2011 - 09:42 PM

Threads are closed after 5 days of inactivity.

ASAP & UNITE Member


The help you receive here is free. If you wish to show your appreciation, then you may Posted Image

#62 User is offline   Chatt 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 37
  • Joined: 10-August 11

Posted 21 August 2011 - 10:38 PM

I tried it, but it didn't seem to work. When I entered the run command, a window flashed up for a fraction of a second and then disappeared. I waited 5 minutes or so, but nothing happened.

#63 User is offline   RPMcMurphy 

  • Bleeping *^#@%~
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 2,397
  • Joined: 16-May 10
  • Gender:Male

Posted 22 August 2011 - 09:19 PM

Chatt:

Posted Image Please download GrantPerms.zip and save it to your desktop.
  • Unzip the file and depending on the system run GrantPerms.exe or GrantPerms64.exe
  • Copy and paste the following in the edit box:

    C:\Users\Owner\Desktop\gmer.exe
    C:\Users\Owner\Desktop\aswmbr.exe
    C:\Users\Owner\Desktop\tdsskiller.exe

  • Click Unlock. When it is done click "OK".
  • Click List Permissions and post the result (Perms.txt) that pops up. A copy of Perms.txt will be saved in the same directory the tool is run.

Please include the following in your next post:
  • grantperms log

Threads are closed after 5 days of inactivity.

ASAP & UNITE Member


The help you receive here is free. If you wish to show your appreciation, then you may Posted Image

#64 User is offline   Chatt 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 37
  • Joined: 10-August 11

Posted 22 August 2011 - 10:36 PM

GrantPerms by Farbar
Ran by Owner at 2011-08-22 22:35:54

===============================================
\\?\C:\Users\Owner\Desktop\gmer.exe

Owner: BUILTIN\Administrators

DACL(P)(AI):
S-1-5-32-547 READ ALLOW (NI)
BUILTIN\Administrators FULL ALLOW (NI)
NT AUTHORITY\SYSTEM FULL ALLOW (NI)
BUILTIN\Users READ/EXECUTE ALLOW (NI)


\\?\C:\Users\Owner\Desktop\aswmbr.exe

Owner: BUILTIN\Administrators

DACL(P)(AI):
S-1-5-32-547 READ ALLOW (NI)
BUILTIN\Administrators FULL ALLOW (NI)
NT AUTHORITY\SYSTEM FULL ALLOW (NI)
BUILTIN\Users READ/EXECUTE ALLOW (NI)


\\?\C:\Users\Owner\Desktop\tdsskiller.exe

Owner: BUILTIN\Administrators

DACL(P)(AI):
S-1-5-32-547 READ ALLOW (NI)
BUILTIN\Administrators FULL ALLOW (NI)
NT AUTHORITY\SYSTEM FULL ALLOW (NI)
BUILTIN\Users READ/EXECUTE ALLOW (NI)

#65 User is offline   RPMcMurphy 

  • Bleeping *^#@%~
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 2,397
  • Joined: 16-May 10
  • Gender:Male

Posted 23 August 2011 - 09:27 AM

Try removing those files from your desktop now.
Threads are closed after 5 days of inactivity.

ASAP & UNITE Member


The help you receive here is free. If you wish to show your appreciation, then you may Posted Image

#66 User is offline   Chatt 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 37
  • Joined: 10-August 11

Posted 23 August 2011 - 03:53 PM

It worked for everything except rkunhooker. Do I need to do the same grantperms operation for rkunhooker too?

#67 User is offline   RPMcMurphy 

  • Bleeping *^#@%~
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 2,397
  • Joined: 16-May 10
  • Gender:Male

Posted 23 August 2011 - 09:25 PM

Yes, just look up the full file path and enter it into GrantPerms like you did the others. You can hang on to GrantPerms and repeat that operation for any other app you find not working as well.

Posted Image Uninstall ComboFix
  • Press the Windows key + R on your keyboard or click Start -> Run. Copy and past the following text into the run box that opens and press OK:
    Combofix /Uninstall

Posted Image

Is there anything else we have not addressed?
Threads are closed after 5 days of inactivity.

ASAP & UNITE Member


The help you receive here is free. If you wish to show your appreciation, then you may Posted Image

#68 User is offline   Chatt 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 37
  • Joined: 10-August 11

Posted 23 August 2011 - 10:26 PM

I think that does it. Stubborn files are gone, and the machine is running well. Thank you so much for your help.

#69 User is offline   RPMcMurphy 

  • Bleeping *^#@%~
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 2,397
  • Joined: 16-May 10
  • Gender:Male

Posted 24 August 2011 - 09:44 PM

You're welcome, chatt. Take care.
Threads are closed after 5 days of inactivity.

ASAP & UNITE Member


The help you receive here is free. If you wish to show your appreciation, then you may Posted Image

#70 User is offline   RPMcMurphy 

  • Bleeping *^#@%~
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 2,397
  • Joined: 16-May 10
  • Gender:Male

Posted 26 August 2011 - 08:24 PM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.
Threads are closed after 5 days of inactivity.

ASAP & UNITE Member


The help you receive here is free. If you wish to show your appreciation, then you may Posted Image

Share this topic:


  • 5 Pages +
  • « First
  • 3
  • 4
  • 5
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users