Author Topic: A Rootkit Whistler@MBR Disk 0 :(((((  (Read 4195 times)

0 Members and 1 Guest are viewing this topic.

BreakinRanh

  • Guest
A Rootkit Whistler@MBR Disk 0 :(((((
« on: April 29, 2011, 03:58:25 AM »
Hi guys, I'm new here, and been getting this alert from Avast! every boot up even though I click the Delete now and restart my computer. I tried googling up other people having this. I have downloaded aswMBR and will post my log. Oddly enough, I cannot click the "fix" button after a scan has gone down. even if I reset my computer. I have also tried Malwarebytes I need help and thank you :).

aswMBR version 0.9.5 Copyright(c) 2011 AVAST Software
Run date: 2011-04-28 18:56:43
-----------------------------
18:56:43.157    OS Version: Windows x64 6.1.7600
18:56:43.157    Number of processors: 2 586 0x301
18:56:43.157    ComputerName: HP-DV4  UserName:
18:56:44.001    Initialize success
18:56:48.012    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
18:56:48.012    Disk 0 Vendor: Hitachi_HTS543225L9A300 FBEOC40F Size: 238475MB BusType: 11
18:56:50.036    Disk 0 MBR read successfully
18:56:50.036    Disk 0 MBR scan
18:56:50.036    Disk 0 Whistler@MBR code has been found
18:56:50.046    Disk 0 MBR [Whistler]  **ROOTKIT**
18:56:50.046    Service scanning
18:56:51.465    Disk 0 trace - called modules:
18:56:51.495    ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
18:56:51.495    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004c36060]
18:56:51.495    3 CLASSPNP.SYS[fffff8800185c43f] -> nt!IofCallDriver -> [0xfffffa8004c35040]
18:56:51.505    5 hpdskflt.sys[fffff880015ef289] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8004bbc060]
18:56:51.515    Scan finished successfully
« Last Edit: April 29, 2011, 04:35:44 AM by BreakinRanh »

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: A Rootkit Whistler@MBR Disk 0 :(((((
« Reply #1 on: April 29, 2011, 11:07:56 AM »
1)scan again and click "FIX MBR" and reboot
2) after reboot, new scan and click "save log" then post that log here in your next reply
« Last Edit: April 29, 2011, 11:30:20 AM by Left123 »
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: A Rootkit Whistler@MBR Disk 0 :(((((
« Reply #2 on: April 29, 2011, 11:25:05 AM »
Quote
1)scan again and click "FIX" and reboot
NO whistler is "FIX MBR"

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: A Rootkit Whistler@MBR Disk 0 :(((((
« Reply #3 on: April 29, 2011, 11:30:40 AM »
Quote
1)scan again and click "FIX" and reboot
NO whistler is "FIX MBR"
Sorry my bad,fixed
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus

BreakinRanh

  • Guest
Re: A Rootkit Whistler@MBR Disk 0 :(((((
« Reply #4 on: May 01, 2011, 07:07:31 AM »
Thanks guys, I was worried to click the other fix button because it said it would change the parition and that it was "risky" haha. You guys are great!

aswMBR version 0.9.5 Copyright(c) 2011 AVAST Software
Run date: 2011-04-30 21:54:23
-----------------------------
21:54:23.814    OS Version: Windows x64 6.1.7600
21:54:23.814    Number of processors: 2 586 0x301
21:54:23.815    ComputerName: HP-DV4  UserName:
21:54:24.602    Initialize success
21:54:26.122    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
21:54:26.124    Disk 0 Vendor: Hitachi_HTS543225L9A300 FBEOC40F Size: 238475MB BusType: 11
21:54:28.142    Disk 0 MBR read successfully
21:54:28.145    Disk 0 MBR scan
21:54:28.148    Service scanning
21:54:29.588    Disk 0 trace - called modules:
21:54:29.608    ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
21:54:29.611    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004c36060]
21:54:29.615    3 CLASSPNP.SYS[fffff8800185c43f] -> nt!IofCallDriver -> [0xfffffa8004c35040]
21:54:29.619    5 hpdskflt.sys[fffff880015ef289] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8004bbc060]
21:54:29.624    Scan finished successfully

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: A Rootkit Whistler@MBR Disk 0 :(((((
« Reply #5 on: May 01, 2011, 10:33:42 AM »
Any other problems?
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus