How to Remove Rootkit Viruses – Or Can You?
Before I give you some tips on rootkit virus removal I feel I must share my story with you of what happened to me so hopefully it doesn’t happen to you – what to watch for – although your experience might be slightly different.
Last Friday, Feb. 17th, 2012, I had just finished up a day long webinar, Builder Bonanza, with WebDesign.com, which was a FABO class!
During classes we are always given links, either by the Professor (aka Benjamin Bradley) or others in the class chat room to great sites that will assist us with our work and web sites. I generally open up the link in a new tab and after class I add them to my favorites (or bookmark them) to be used or reviewed later.After I did this I was checking out some links from a potential vendor for doing some work for a potential client. I was visiting one of the vendor’s previous client’s Twitter home page and all of a sudden my computer flashes back to my desktop, a box popped up, called “System Checker”, with the Microsoft™ flag logo on it and it began to run, and in my start up balloons started popping up telling me my hard drive was about to crash, I was out of memory, and on and on it went all the while this “System Checker” is running.
I could NOT close it out or stop it from running!!!
Please note that I am not inferring that any of the links I was visiting from class or vendor gave me the rootkit virus – I could have had it for a while and it decided to “pop up it’s ugly head” when it did!
After the “System Checker” stopped running it said I had to buy it to finish fixing all my problems – and then I knew my computer was in BIG trouble!! And I could NOT close out this “System Checker” box.
And EVERYTHING disappeared from my desktop, my task bar and my start up menu, except for three icons. I don’t recall now what icons were left because I was FREAKING out!!!!!
I had access to nothing except those three icons, couldn’t see any of my files – zip, gone – “lost”!
So I hysterically phone my computer repair guy – by this time it’s about 7PM – and FREAK out on him a little …..
He tells me he can come by on Sat. at 10AM and I say, “I’m going out of town so I’ll make sure hubbie is here to let you in”. I am calm and confident that he can fix this problem.
By noon on Sat. I get the call he hasn’t been able to do anything could he take my computer home and work on it over weekend – Sure – Please have it back on Mon. by 10AM.
Long story short – He couldn’t fix it – which surprised me (he did say he got rid of the virus – Well you will soon see he DID NOT); however the GOOD news was ALL my files and programs where still on my computer, they were just “hidden” by the rootkit virus. He knew this because he ran a Linux program on my computer and could see everything – just couldn’t get to anything.
He suggested I purchase another laptop ( a cheap one – for around $400) until we could figure this out!!!
My expression: IS he CRAZY! I’m not made of money!!!
My computer is top dollar and I’m still paying for it – Dell’s Precision M6500, starting out at over $2000.00 and I have ALL the bells and whistles! (I knew I should have brought a MAC!!!)
This NOT being what I wanted to hear I decide to call my son in NC who is a Virus Remover, Computer Repairman EXPERT and does this day in and day out for a living for the past 10 years or so.
Me: Son, I’ve been attacked by a virus and now I can’t see any of my files or programs – PLEASE HELP ME!!!
Son: Can you get on the Internet?
Me: Yes
Son: Sounds like you have a rootkit virus. Here are the steps I want you to take:
Rootkit Virus Removal Steps That “Might” Help You
WARNING: You might NOT need to do all these steps and might need HELP with some – Caution!
1. Download and run ComboFix – I did – I’ll tell you about that in a sec.
2. Download and run TDSSKILLER – What a time I had to get this – I’ll tell you about that in a sec.
3. Go to the DOS command and type in atribe – this was a mumble from him so not sure if that is what he said – and I didn’t get that far as you will see if you continue reading. I hope you do because I have some other important things to share with you.
4. If all else fails try using unhide.exe
ComboFix
It took a while to get the “right” ComboFix – (use the link I gave you above). Got it, downloaded and ran it. It ran for about FOUR hours!
When it finished I was presented with a text log and I printed it out, just in case someone needed to read it.
I restarted my computer and PRAYED!!!
I gave my computer Reiki
And I would have stood on my head if that would help – if I could stand on my head!
So my screen comes back on and there appear to be only those three icons!
I’m sure I swore some selected curse words and THEN out of the corner on my left eye in the top left corner of my desktop I noticed a WORD doc icon on the screen!
That wasn’t there before I ran ComboFix – so I clicked on it…
…MAGIC!
ALL my desktop icons and start up menus came back!!!!!
Hallelujah – Praise the Lord and my son!!!
But wait – where are my task menu items?
I click on Start all Programs – I click on several different folders – it says EMPTY!!!
More Freaking out – then calm – look in My Computer – and to my surprise EVERYTHING was there and I could open anything I clicked on.
Needless to say I did the happy dance and called my son to tell him how wonderful he was and asked if I should do step two: Download and run TDSSKILLER
TDSSKILLER
Son: Wouldn’t hurt
So I make him stay on the phone with me as I track down the link and WAIT a MINUTE!!!!
I click on the links – any links that say they have TDSSKILLER and every link takes me to a DIFFERENT web site with all these ads on them!
Son: Mom, you still have a virus!!
Oh GOD!!!!
So I discovered if I copied and pasted the link into the browser I could navigate to the correct page.
I download TDSSKILLER, click to run it and NOTHING!
It won’t run!!!
Son: Rename the file to iexplore.com
I rename it, click, nothing – it just won’t run.
Son: When I get home from work I’ll do a remote with you and check it out.
So later we do a remote viewing (we used teamviewer).
Son: Just mail your computer to me and I’ll fix it – I really can’t do anything from here.
I thought: Is he CRAZY? Mail my “precious” to NC!!!!!
Me: I’d rather not do that. Let me call one more local computer person, actually my old computer repair person I had just found out that weekend was back in MD.
So he comes over on Monday, evaluates the situation and tells me the virus is too DEEP into my system. The best thing to do is wipe it clean and reinstall everything.
I thought: Is he CRAZY? Does he realize how much “STUFF” I have on this computer and how many programs I would need to reload!!!!
Anyway, I reluctantly give in to this.
We did a double back up of my docs, my pics, my videos, my bookmarks, and all my email.
He tells me the steps I need to do and leaves because this is going to take a long time – call him later and he’ll take me through the rest of the steps over the phone.
Well I couldn’t get my computer to recognize the reboot CD – hit any key – I hit them all and nothing was happening!
So back to my son I call.
Son: MOM – DO NOT DO THAT!
He had me do a lot of things and then we did a remote, another type of box pops up about viruses and wants to run, and then, and then, I was stuck at Windows Starting – that’s it -frozen.
Son: Just mail me the damn thing! I can fix it for you and you won’t lose anything or need to reload all your programs.
As of 15 minutes ago, this Friday the 24th, my computer has arrived at his home in NC.
I see him using all his tools and knowledge to remove the rootkit virus once and for all and get me up and running again.
BTW – son is calling this the rootkit.boot.piranha virus; however I think that might be a name he gave it! LOLOLOL
Total cost out of my pocket so far: $388 – maybe I should have brought a cheap computer – LOLOLOL
So there you have my story (and why I haven’t blogged in a week – I’ve been busy) and some rootkit virus removal steps; however I HOPE this never happens to you!
Update: Sat., Feb. 25, 2012 son called at 10:30 AM to tell me my computer is fixed and back in tack! NO wiping the hard drive or reinstalling – YIPEE!!! He is the BEST!! Packing it up to ship back to me today – that’s what I call real service and expertise. Thanks son! The virus was rootkit.boot.bb (not sure about the bb part)
If you have read this far then I’d like to ask you a few questions:
1. What anti virus software do you use and love?
2. Have you ever had the rootkit virus and what did you do?
3. What downloads did you use to get rid of it?
Please leave your comments, suggestions, or ideas below and if you found this helpful please also tweet, FB, Google + or what ever you want to do to let others know about my story with the rootkit virus!