Avast WEBforum

Other => Viruses and worms => Topic started by: xAOx on March 20, 2012, 09:20:10 PM

Title: Rootkit found - but what does it mean?
Post by: xAOx on March 20, 2012, 09:20:10 PM
Hello all, an alert from avast! popped up says "Rootkid Found" but the file name is pointing to MBR: \\.\PHYSICALDRIVE0\PARTITION3 and the action to take is Delete Now or Ignore. I am fairly certain that on my one harddrive, Partition 3 is where the OS resides. So if I choose to "Delete Now" is that going to harm the MBR and not let me load into Windows? And if I choose to Ignore, is this a real root kit somehow on my PC or a false-alarm?

Any help would be appreciated!
Title: Re: Rootkit found - but what does it mean?
Post by: essexboy on March 20, 2012, 10:33:05 PM
Hi lets check it out

Download aswMBR.exe (http://public.avast.com/~gmerek/aswMBR.exe) ( 4.1mb ) to your desktop.
 Double click the aswMBR.exe to run it  Click the "Scan" button to start scan 

(http://i1224.photobucket.com/albums/ee362/Essexboy3/aswMBR%20shots/aswMBRScan.gif)

On completion of the scan click save log, save it to your desktop and post in your next reply

(http://i1224.photobucket.com/albums/ee362/Essexboy3/aswMBR%20shots/aswMBRsavelog.gif)
Title: Re: Rootkit found - but what does it mean?
Post by: xAOx on March 21, 2012, 03:57:54 PM
Nothing happens when I double-click the program. Tried in regular and safe mode windows.
Title: Re: Rootkit found - but what does it mean?
Post by: essexboy on March 21, 2012, 09:20:41 PM
OK lets have a look at your partitions

Quote
Do the following:
Start -> Run
type diskmgmt.msc
Click "OK"
 
Disk Management will open.
 
Click and hold the right side of the Disk Management Window and drag it to the right until you can see all the columns.
 
Take a screen Shot of the Disk Management Window and attach the screen shot to your reply.

THEN

Download OTL (http://oldtimer.geekstogo.com/OTL.exe)  to your Desktop
netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
consrv.dll
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
/md5stop
C:\Windows\assembly\tmp\U\*.* /s
%Temp%\smtmp\1\*.*
%Temp%\smtmp\2\*.*
%Temp%\smtmp\3\*.*
%Temp%\smtmp\4\*.*
>C:\commands.txt echo list vol /raw /hide /c
/wait
>C:\DiskReport.txt diskpart /s C:\commands.txt /raw /hide /c
/wait
type c:\diskreport.txt /c
/wait
erase c:\commands.txt /hide /c
/wait
erase c:\diskreport.txt /hide /c
CREATERESTOREPOINT

Title: Re: Rootkit found - but what does it mean?
Post by: xAOx on March 21, 2012, 10:30:58 PM
Unfortunately, I can neither paste (exceeds 1000 characters) or attach the documents (says its full).
I zipped ad uploaded them here - http://www.sendspace.com/file/pqyjo3

THANK YOU in advance!
Title: Re: Rootkit found - but what does it mean?
Post by: essexboy on March 21, 2012, 10:40:41 PM
here (http://support.kaspersky.com/downloads/utils/tdsskiller.exe) and save it to your Desktop.
 
 
A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste its contents on your next reply.
[/list]
Title: Re: Rootkit found - but what does it mean?
Post by: xAOx on March 21, 2012, 10:53:51 PM
Thanks for that program.

Very interesting- so i finally have a name for this rootkit, it is rootkit.boot.sst.b .
Title: Re: Rootkit found - but what does it mean?
Post by: essexboy on March 21, 2012, 10:59:16 PM
Could you upload the log please as there are probaly some remnants to remove
Title: Re: Rootkit found - but what does it mean?
Post by: xAOx on March 21, 2012, 11:08:30 PM
I could not attach because of a forum issue so please see the attached tds log here-
http://www.sendspace.com/file/r487u6

thanks!
Title: Re: Rootkit found - but what does it mean?
Post by: essexboy on March 21, 2012, 11:11:11 PM
How is the computer behaving now ?
Title: Re: Rootkit found - but what does it mean?
Post by: xAOx on March 24, 2012, 02:52:20 AM
Unfortunately I get endless BSOD in Windows and even Safe Mode. I am considering giving up and formatting - but here's the question - with this being a "bootkit" virus, is it possible that even after a format and Windows reinstall that the virus will appear?
Title: Re: Rootkit found - but what does it mean?
Post by: essexboy on March 24, 2012, 01:50:52 PM
As it was a mbr malware you will need to reformat the disc to ensure that it has gone

When you get the Blue screen what is the error reported
Title: Re: Rootkit found - but what does it mean?
Post by: xAOx on March 24, 2012, 03:24:58 PM
The typical blue screen "a problem has been detected..." STOP error is 0x followed by a series of zeros and 7E.
Thank you for your continued assistance...
Title: Re: Rootkit found - but what does it mean?
Post by: essexboy on March 24, 2012, 03:37:27 PM
Are you able to access the safe mode menu ?

If so select Last Known  Good
Does that get you back ?

Do you have a windows CD as we can then use that next