New fake A/V Win HDD removal

Kitten Kong

Administrator
Staff member
Reaction score
3,425
Location
Manchester UK
I've had this bar steward in two machines this week, and it's been a b1tch to get rid of!. At one point, I thought the easiest way of sorting these would be a N&P!.

Now im pretty sure the machines were infected with far more than the simple rogue a/v, but this is the track I took to remove the virus, and clean the machines.

Malwarebytes, updated quick scan - Did not remove it completely. done in normal mode.
Smitfraud fix - found issues, and fixed them. Safe mode.
Hitman pro - found issues and fixed them all.
TDSS rootkit, found 1 issue - fixed.

Thought great, pc working. go online, and browser hijacked each time.

Hijack this, manual removal, removed quite a few issues - Browser hijack fixed.

Still WinHDD was there!.

Autoruns, cleared
Process explorer, cleared.

Combofix. Cleared everything. Safe mode

MBAM - updated again, run normal mode, full scan. Removed WinHdd!

All in all, it took approx 4 - 6 hours to remove this, and everything else on the pc.

There were trojans, a couple of rootkits, the usual mywebsearch, false windows security alerts, browser hijacks, you name it, it was there.

All this for my flat rate of £35, for virus / malware removal. At times, I wish I charged pr hour lol.

One of the machines, was a build from me a couple of years ago, for a good friend.

The other was a netbook, less than a month old, I sold to another good friend. The netbook's owner is 18, was given this for her birthday present in Nov. She leant it to a 'friend', who since admitted he had a look at a porn site, and was infected.

Kudos to him for letting me know. I tried to find out exactly which site infected them, with ieview, but my client thought they would roll back the machine, and in so doing that, all the sites visited were lost etc.

Just a heads up, if anyone has a similar issue with this virus. You could be in for the long haul.
 
Thanks for your tip. Got one on my bench now was going to start it after corrie. I hoped it would be a simply manual removal but looks like I am not in luck. It is Windows vista but there is no COA on it either :(.
 
So far everything seems to be going ok. Malwarebytes found a few things but was useless (an increasingly common trend). Process explorer has revealed the fake HDD programs and I have deleted them.

Had the usual DNS and proxy hijacks but so far it dosn't seem that bad but it always depends on the system as each PC always has different malware installed on it.

Will do an offline scan and also check for rootkits. What usualy happens though is I think it is an easy fix and I discover the damn rootkits.
 
The problem is I am not sure relating on TTDSKILLER is enough now. Some of these new rootkits go as far as even making explorer.exe use routed function calls. That means when doing a manual scan you cannot trust what is being reported.

Still working on the fake HDD infection. That was a doddle to fix but it is all the other crap which takes some time, it looks like he had been running a fake AV since May!
 
Back
Top