Boot sector Virus removal: CIDOX

mtnscott

New member
Local time
6:50 AM
Messages
1
I'm helping a friend who is having a problem removing a boot virus on her Windows 7 system. She bought Norton360, installed it and worked with their support team to remove this virus. They found and removed other viruses, but they were unable to remove this particular virus. She utilizes my network to access the Internet and my ISP indicated that they were receiving spam generating traffic from my network. Here's the message they sent me:

This malicious traffic has been determined to be an instance of the "Zero Access" rootkit (also known as "Sireref").

Norton gives an indication on her computer that she has a boot trojan with the name: CIDOX.

Does anyone have a suggestion on how to clean her computer completely and removal all instances of virus and malware? She does have a Recovery set of disks that she created when she first activated her computer.

Thanks for any help that you can give.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HP
OS
Windows 7 32 bit
Antivirus
Norton 360

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
...or, we can take a good shot at it...


:info: Please download the Farbar Recovery Scan Tool:
Link:Farbar Recovery Scan Tool Download
Select the version that applies to your system.
Save it to your Desktop.

Double-click the downloaded file to run it.
When the tool opens click Yes to the disclaimer.

Press the Scan button.

The tool makes a log (FRST.txt) in the same directory from which the tool is run (Desktop).
:ar: Please provide the FRST.txt in your reply.

The first time the tool is run, it also makes another log: Addition.txt
:ar: Also post the Addition.txt in your reply.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
ya, you could try and tackle it, but my experience with these kind of rootkits says do a full reinstall. It will absolutely kill that virus. You will have to save all important data/files etc first, when doing a full install as all data will be lost. Just my thoughts.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Dell Latitude E6410
OS
Windows 7 Home Premium (64 bit)
CPU
Intel I5 520m
Memory
8 GB
Graphics Card(s)
Intel integrated
Sound Card
IDT Digital Audio
Monitor(s) Displays
Dell ST2010
Screen Resolution
1600X900
Hard Drives
WD Scorpio Black 750GB
Keyboard
Microsoft Wireless Comfort Keyboard 5000
Mouse
Microsoft Wireless Mouse 5000
Internet Speed
350 mb/s down 12 mb/s up
Antivirus
NIS
Browser
Firefox
Other Info
Repaired trash lappy
You could also run TDSSKiller, which removes most rootkits.

TDSSKiller Rootkit Removal Utility Free Download | Kaspersky Lab US

However, malware tends to invite others to the table & if you want to be sure it's gone, a clean re-install is the way to go.

Be sure to format/wipe the disk before doing the reinstall as some rootkits have been known to survive a reinstall. Rootkits are known to write hidden boot partitions, so these must be eliminated from the disk.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Hell oh Well
OS
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
CPU
Intel Core 2 Duo 2.93GHz
Memory
Not much with my ADHD
Graphics Card(s)
ATI Radeon HD 4350
Monitor(s) Displays
24" HDTV/Monitor
Screen Resolution
Blurry after a Scotch or 2
Hard Drives
1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
Case
Don't get on my case...man :D
Cooling
I have an Air Conditioner & Diet Pepsi
Keyboard
Saitek Cyborg
Mouse
10 yr old MS optical mouse that still works
Internet Speed
Never fast enough
Antivirus
Various
Browser
Various
Rootkits are known to write hidden boot partitions, so these must be eliminated from the disk.

True!

...and there are tools that target these:

This malicious traffic has been determined to be an instance of the "Zero Access" rootkit (also known as "Sirefef").

Norton gives an indication on her computer that she has a boot trojan with the name: CIDOX.

However, at this point, we may have lost the OP!!
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Back
Top