Author Topic: Rootkit - MBR: \\.\PHYSICALDRIVE0  (Read 3635 times)

0 Members and 1 Guest are viewing this topic.

Siyanaify

  • Guest
Rootkit - MBR: \\.\PHYSICALDRIVE0
« on: June 26, 2011, 09:59:31 PM »
My Avast! scan logs keep saying I have a rootkit called "MBR:\\.\PHYSICALDRIVE0" which I've tried to send to chest several times to no avail. It doesn't show up on the boot scans and I've had blue screen twice so far; once last night when I first got the rootkit and again today when I turned on my networking. When I managed to get it into safe mode, my laptop restarted itself before I could do anything.

Any help on fixing this will be much appreciated.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: Rootkit - MBR: \\.\PHYSICALDRIVE0
« Reply #1 on: June 26, 2011, 10:04:09 PM »
You can check if you have an MBR rootkit using this tool:
Quote from: essexboy
Download aswMBR.exe ( 1.8MB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan

 
On completion of the scan click save log, save it to your desktop and post in your next reply



Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Siyanaify

  • Guest
Re: Rootkit - MBR: \\.\PHYSICALDRIVE0
« Reply #2 on: June 26, 2011, 10:19:37 PM »
I tried running it and I got blue screen. I tried again in safe mode only to get a blue screen again. The error I got was "DRIVER_IRQS_NOT_LESS_OR_EQUAL" What should I do?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: Rootkit - MBR: \\.\PHYSICALDRIVE0
« Reply #3 on: June 26, 2011, 11:42:49 PM »
You can try another rootkit tool, but if that can't run either, I don't know if that is down to the existing rootkit blocking security tools.

Quote from: essexboy

Second opinion now

Please read carefully and follow these steps. 
  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
     

     
     
  • If an infected file is detected, the default action will be Cure, click on Continue.
     

     
     
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
     

     
     
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
     

     
     
  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.

Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Siyanaify

  • Guest
Re: Rootkit - MBR: \\.\PHYSICALDRIVE0
« Reply #4 on: June 27, 2011, 12:11:44 AM »
Okay, I scanned it successfully. Here is the log. I removed the unimportant stuff.

Code: [Select]
2011/06/26 18:00:34.0734 1840 \Device\Harddisk0\DR0 - detected Rootkit.Win32.TDSS.tdl4 (0)
2011/06/26 18:00:34.0765 1840 ================================================================================
2011/06/26 18:00:34.0765 1840 Scan finished
2011/06/26 18:00:34.0765 1840 ================================================================================
2011/06/26 18:00:34.0781 1152 Detected object count: 1
2011/06/26 18:00:34.0781 1152 Actual detected object count: 1
2011/06/26 18:00:53.0111 1152 \Device\Harddisk0\DR0 (Rootkit.Win32.TDSS.tdl4) - will be cured after reboot
2011/06/26 18:00:53.0111 1152 \Device\Harddisk0\DR0 - ok
2011/06/26 18:00:53.0111 1152 Rootkit.Win32.TDSS.tdl4(\Device\Harddisk0\DR0) - User select action: Cure
2011/06/26 18:01:03.0797 1844 Deinitialize success

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: Rootkit - MBR: \\.\PHYSICALDRIVE0
« Reply #5 on: June 27, 2011, 01:20:40 AM »
OK as the log says you will need to reboot to effect the cure. If you haven't done that then do so.

Let us know if avast alerts again after the reboot.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Siyanaify

  • Guest
Re: Rootkit - MBR: \\.\PHYSICALDRIVE0
« Reply #6 on: June 27, 2011, 01:36:13 AM »
Already done. Thank you so much for all your help. :)

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: Rootkit - MBR: \\.\PHYSICALDRIVE0
« Reply #7 on: June 27, 2011, 02:19:58 AM »
No problem, glad I could help.

Welcome to the forums.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security