Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: MBR Faked, Olmarik.TDL4 & Alureon.E  (Read 7954 times)

0 Members and 1 Guest are viewing this topic.

dust4life

    Topic Starter


    Starter
    • Certifications: List
    • Computer: Specs
    • Experience: Experienced
    • OS: Windows 7
    MBR Faked, Olmarik.TDL4 & Alureon.E
    « on: December 07, 2011, 09:06:49 PM »
    Hey guys, I've got my hands full with this latest issue.

    Long story short, I picked up the GoogleUpdater.exe virus and now have a couple trojan's I'm incapable of removing.

    Booting into the Windows Defender Standalone (http://connect.microsoft.com/systemsweeper) I can see an Alureon.E trojan in my boot drive [listed as boot:\\.\PHYSICALDRIVE0\Partition2 (Type 17)] but the program can't remove it.

    Trial install of NOD32 notes a Win32/Olmarik.TDL4 trojan which also can't be accessed.

    Had to download the unsigned version of Kaspersky's TDSSKiller.exe to actually get it to run, but it didn't find anything useful. I am unable to run Avast!'s rootkit tool, even after renaming it and changing the extension to a .com file. Task pops up in my manager then disappears.

    Used MBRCheck.exe to take a look at my MBR, it lists the MBR of \\.\PhysicalDrive0 (my only drive) as "MBR Code Faked!"
    MBRCheck's repair tool runs successfully but a restart and a rescan yields the same results.

    Threw in my Win 7 disk and tried to fix the MBR through the repair command prompt, but using both
    >bootrec /fixmbr
    >bootrec /fixboot

    didn't change anything, though they ran successfully. I also tried grabbing bootsect.exe right from the install disk through
    >bootsect /nt60 SYS /mbr

    but was given one access error, followed by a notation of Success on physicaldrive0 (I can rerun if the exact output is needed)

    I'd rather not throw logs at you guys without being prompted but since I've been taking every shot I could think of at this thing I've got a pretty solid collection of scanners if you're looking for some output:

    MBRCheck
    OTL
    MWB Anti-Malware
    Spybot S&D
    Symantec EP 12
    Trendmicro SysClean (my old favorite from XP, but i think its got x64 issues...)
    ESET NOD32 (trial)
    Microsoft Security Essentials
    HJT

    I'd prefer not to reinstall my OS, but I guess I can if thats my only option...

    System is running Windows 7 Pro x64 SP1

    Thanks in advance guys

    Mike

    SuperDave

    • Malware Removal Specialist


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Re: MBR Faked, Olmarik.TDL4 & Alureon.E
    « Reply #1 on: December 08, 2011, 12:53:30 PM »
    Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer.

    1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
    2. The fixes are specific to your problem and should only be used for this issue on this machine.
    3. If you don't know or understand something, please don't hesitate to ask.
    4. Please DO NOT run any other tools or scans while I am helping you.
    5. It is important that you reply to this thread. Do not start a new topic.
    6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
    7. Absence of symptoms does not mean that everything is clear.

    If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
    *************************************************************************
    Let's run a few more scans to see what turns up.

    Please download aswMBR.exe ( 511KB ) to your desktop.

    Double click the aswMBR.exe to run it



    Click the "Scan" button to start scan

    Note: Do not take action against any **Rootkit** entries until I have reviewed the log. Often there are false positives



    On completion of the scan click save log, save it to your desktop and post in your next reply
    Windows 8 and Windows 10 dual boot with two SSD's

    dust4life

      Topic Starter


      Starter
      • Certifications: List
      • Computer: Specs
      • Experience: Experienced
      • OS: Windows 7
      Re: MBR Faked, Olmarik.TDL4 & Alureon.E
      « Reply #2 on: December 08, 2011, 03:49:30 PM »
      Hey Dave, thanks for the reply

      After seeing the Alureon.E trojan, I grabbed the Kaspersky and Avast! rootkit scanners but couldn't run either.

      Wandering the kaspersky forums yielded an unsigned version of their TDSSKiller program which I can run (doesn't find anything), but as the Avast! scanner pops up as an "Avast!" program it shows up in my task manager for a second but gets terminated.

      dust4life

        Topic Starter


        Starter
        • Certifications: List
        • Computer: Specs
        • Experience: Experienced
        • OS: Windows 7
        Re: MBR Faked, Olmarik.TDL4 & Alureon.E
        « Reply #3 on: December 20, 2011, 07:28:46 PM »
        for anyone wondering as to the remedy for this problem, I happened to have my windows install disk on hand... and just went for it. After a clean install, my MBR's all good, the awkward unknown user with admin privileges is gone and everything's all better. Too bad I have to reinstall all my programs...

        SuperDave

        • Malware Removal Specialist


        • Genius
        • Thanked: 1020
        • Certifications: List
        • Experience: Expert
        • OS: Windows 10
        Re: MBR Faked, Olmarik.TDL4 & Alureon.E
        « Reply #4 on: December 21, 2011, 11:34:12 AM »
        for anyone wondering as to the remedy for this problem, I happened to have my windows install disk on hand... and just went for it. After a clean install, my MBR's all good, the awkward unknown user with admin privileges is gone and everything's all better. Too bad I have to reinstall all my programs...
        Well, that was a quick fix. I hope you didn't lose any important data. I will lock this thread. If you need it re-opened, please send me a pm.
        Windows 8 and Windows 10 dual boot with two SSD's