Avast WEBforum

Other => Viruses and worms => Topic started by: REDACTED on November 26, 2014, 06:53:15 PM

Title: MBR:Cidox-E [rtk] - Avast can not remove
Post by: REDACTED on November 26, 2014, 06:53:15 PM
Hi - I am helping a friend recover their laptop. I think it's mostly clear except for the Cidox-E rootkit.

This is also discussed in
Code: [Select]
https://forum.avast.com/index.php?topic=161457.0 and I have already ran TDSSKiller which did not find anything.

I have attached the FRST logs. Do you need any others? Many thanks in advance for any help! :)
Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: essexboy on November 26, 2014, 07:31:33 PM
Could you attach the TDSSKiller log please

Download the attached fixlist to the same location as FRST
Start FRST and press Fix
After the reboot a log will open please attach that

THEN

Please download AdwCleaner (http://www.bleepingcomputer.com/download/adwcleaner/) by Xplode onto your desktop.
Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: REDACTED on November 26, 2014, 08:14:00 PM
TDSSKiller logs on next reply. Thank you!
Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: REDACTED on November 26, 2014, 08:15:44 PM
TDSSKiller logs
Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: essexboy on November 26, 2014, 08:23:56 PM
Could you resave the TDSSKiller log as ANSI please

Could you download and then run Listparts from here :
http://www.bleepingcomputer.com/download/listparts/

When the programme has finished a results.txt will be created please attach that
Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: REDACTED on November 26, 2014, 08:34:55 PM
Here they are (in ANSI)
Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: essexboy on November 26, 2014, 09:35:34 PM
Hmm yet TDSSKiller does not see it nor listparts

One more check

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1  (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here  (http://forums.whatthetech.com/How_Disable_your_Security_Programs_t96260.html&pid=494216#entry494216)
(http://img.photobucket.com/albums/v706/ried7/NSIS_disclaimer_ENG.png)

(http://img.photobucket.com/albums/v706/ried7/NSIS_extraction.png)

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: REDACTED on November 26, 2014, 09:38:09 PM
I ran ComboFix earlier. Here is the log, let me know if I should re-run it
Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: essexboy on November 26, 2014, 09:41:18 PM
Is Avast still reporting cidox ?

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
C:\awhEE06.tmp
C:\awh614C.tmp
C:\awh7CDC.tmp
C:\awh8B9B.tmp
C:\awh621C.tmp
C:\awh77FC.tmp
C:\awh7280.tmp
C:\awh7A7C.tmp
C:\awhD01A.tmp
C:\awh70CB.tmp
C:\awhB6B1.tmp
C:\awhD864.tmp
C:\awh697B.tmp
C:\awh5D3C.tmp
C:\awhFE00.tmp
C:\awh42AA.tmp 
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe
(https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG)
Run FRST and press Fix
On completion a log will be generated please post that
Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: REDACTED on November 26, 2014, 09:55:13 PM
Yes, aswMBR shows it once the scan is started... it still crashes at atapi.sys though. It usually takes a while after the reboot for Avast 2015 to show the pop-up window... and it just did ;)

Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: essexboy on November 26, 2014, 10:40:52 PM
Still not seeing it, yet another look at it

Please download MBRCheck.exe (http://download.bleepingcomputer.com/rootrepeal/MBRCheck.exe) to your Desktop. Run the application.

If no infection is found, it will produce a report on the desktop. Post that report in your next reply.

If an infection is found, you will be presented with the following dialog:

Quote
Enter 'Y' and hit ENTER for more options, or 'N' to exit: 

Type N and press Enter. A report will be produced on the desktop. Post that report in your next reply.
Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: REDACTED on November 26, 2014, 10:59:43 PM
MBRCheck log. Found something...
Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: Pondus on November 27, 2014, 12:20:47 AM
Essexboy has logged out for today, check back tomorrow

Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: essexboy on November 27, 2014, 04:07:43 PM
Run MBRCheck.exe once again.

You will be presented with the following dialog:

Quote
Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:

Enter Y and press Enter.

The following dialog will be presented:
Quote
Options:
[1] Dump the MBR of a physical disk to file.
[2] Restore the MBR of a physical disk with a standard boot code.
[3] Exit.

Enter your choice:

Enter 2 and press Enter

The following dialog will be presented:

Quote
Enter the physical disk number to fix (0-99, -1 to cancel):

Enter >>0<< and press Enter

The following dialog will be presented:
Quote
Available MBR codes:
[ 0] Default (Windows XP)
[ 1] Windows XP
[ 2] Windows Server 2003
[ 3] Windows Vista
[ 4] Windows 2008
[ 5] Windows 7
[-1] Cancel

Please select the MBR code to write to this drive:

Enter >>3<<  and press Enter

The following dialog will be presented:
Quote
Do you want to fix the MBR code? Type 'YES' and hit ENTER to continue:

Type YES and press Enter (Must type the full word, YES). You will be inform if successfully wrote a new MBR code!

And last the following dialog will be presented:

Quote
Done! Press ENTER to exit...

Press Enter. A report will be produced on the desktop. Post that report in your next reply.
Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: REDACTED on November 27, 2014, 04:33:26 PM
And, the results!
Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: essexboy on November 27, 2014, 04:38:32 PM
Is Avast still alerting ?
Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: REDACTED on November 27, 2014, 04:57:41 PM
Unfortunately, yes
Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: essexboy on November 27, 2014, 06:24:59 PM
Could you run AswMBR once again please and we will see if that can fix it
Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: REDACTED on November 28, 2014, 07:01:47 PM
It is still crashing at atapi.sys during the services scan.
Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: essexboy on November 28, 2014, 10:15:41 PM
That is Avast anti rootkit and has not been updated for at least a year

Download aswMBR.exe (http://files.avast.com/files/rootkit-scanner/aswmbr.exe) ( 4.5mb ) to your desktop.
Double click the aswMBR.exe to run it.
You may be offered the option of using virtualisation, accept that
When it offers to download the virus database allow that as well
Click the "Scan" button to start scan

(https://dl.dropboxusercontent.com/u/73555776/AswMBR%20scan.JPG)


On completion of the scan click save log, save it to your desktop and post in your next reply
Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: REDACTED on November 29, 2014, 03:14:30 PM
The log I attached may not be the most recent, in fact it may have been create during a scan in safe mode. But that is the same version I have been running. It crashes at atapi.sys every time.
Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: essexboy on November 29, 2014, 03:49:41 PM
Hmm this is weird as none of the other tools are even hinting at cidox

So lets run a scan with windows and the MBR inactive

Create an emergency repair USB drive:
Download Dr Web Live USB (http://www.freedrweb.com/liveusb/?lng=en) to your desktop
(https://dl.dropbox.com/u/73555776/liveusb_ru.jpg)
(https://dl.dropboxusercontent.com/u/73555776/Live%20boot%20screen.png)

(https://dl.dropboxusercontent.com/u/73555776/drwebselect.JPG)

(https://dl.dropboxusercontent.com/u/73555776/drwebfolders.JPG)

(https://dl.dropboxusercontent.com/u/73555776/drwebscan.JPG)

(https://dl.dropboxusercontent.com/u/73555776/drwebscancomplete.JPG)
Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: REDACTED on December 01, 2014, 01:52:51 PM
I ran the scanner a few times and it found around 50 or so items to fix and fixed them. I never did see the option to "open report" but I found the name of the log file in the help section and did a search for it. It's too big so I split it up into 3 parts. There are 2 - 4 items that it repeatedly finds in between scans and booting into windows. Something about UserInit if I remember correctly.
Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: REDACTED on December 01, 2014, 01:53:25 PM
Part 2 of 3
Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: REDACTED on December 01, 2014, 01:53:56 PM
Part 3 of 3
Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: essexboy on December 01, 2014, 07:06:29 PM
Is Avast still alerting ?
Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: REDACTED on December 01, 2014, 07:07:36 PM
Yes, Avast is still alerting
Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: essexboy on December 01, 2014, 07:34:47 PM
Could you do the following :

Go to > Control panel > administrative tools > computer management > storage > disc management
Then take a screen shot and post it here

 
Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: REDACTED on December 01, 2014, 07:42:39 PM
Screenshot
Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: essexboy on December 01, 2014, 07:45:58 PM
Have you tried the Delete now option ? 

It looks as though it may be alerting on the 10Gb EISA partition which is a restore partition
Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: REDACTED on December 01, 2014, 07:50:09 PM
Yes, I have. It requests to schedule a boot scan and restart the computer, but it is not found during the boot scan and removed.
Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: essexboy on December 01, 2014, 08:35:27 PM
As it stands none of my tools have found it so I believe it is a false alarm on your recovery partition

If there was even a trace then TDSSKiller or DrWeb would have seen it.

Tick the do not alert again box
Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: REDACTED on December 02, 2014, 04:22:11 PM
OK, will do. Thanks so much for the help! Happy holidays!!! :D
Title: Re: MBR:Cidox-E [rtk] - Avast can not remove
Post by: essexboy on December 02, 2014, 04:23:21 PM
Subject to no further problems   :)

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems 

Now the best part of the day ----- Your log now appears clean  :thumbsup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset  System Restore points:

Remove Combofix

Click  Start  then Run.
On Windows7 or Vista  you may use  Start Search  field if  Run  is not available.
In the box copy/paste the following command:

ComboFix  /Uninstall

Note that there is a space between "  ComboFix  " and "  /Uninstall  " .

Then click  OK  (or press  Enter ).
Wait for the uninstall process to complete.

Remove tools

Download and run Delfix (http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/9-delfix)

(https://dl.dropboxusercontent.com/u/73555776/delfix.JPG)

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:

CryptoPrevent (http://www.foolishit.com/vb6-projects/cryptoprevent/) install this programme to lock down and prevent crypto ransome ware

(https://dl.dropboxusercontent.com/u/73555776/CryptoPrevent.JPG)

Malwarebytes (http://www.malwarebytes.org/mbam-download.php).

Update and run weekly to keep your system clean

Unchecky (http://unchecky.com/)

Click on the link above to be taken to Unchecky.com
click the very large Download button.
click Save
Click Open folder
Right click on the Unchecky_setup and choose to Run as Administrator
Once open click the Install button.
Then click on Finish
Unchecky is now installed and will help you keep unwanted check boxes unchecked, this is a fire and forget programme  ;)

It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To learn more about how to protect yourself while on the internet read this little guide  Best security practices  (http://www.bleepingcomputer.com/forums/t/407147/answers-to-common-security-questions-best-practices/)Keep safe  :wave: