Author Topic: Root kit, aswMBR.exe Bsod  (Read 5943 times)

0 Members and 1 Guest are viewing this topic.

Bogartbc

  • Guest
Root kit, aswMBR.exe Bsod
« on: August 25, 2012, 05:35:44 PM »
Found a root kit yesterday after Cold Booting.  Deleted it with Avast then ran the prompted scan.  This came up clean.  I ran a full scan over night that came up clean.  I checked my auto starts finding a setwallpaper Unknown c:\programdata\setwallpaper.cmd.  I couldn't find this file with folder options set to show hidden, os folders, etc.  I couldn't find anything on MS about it.  I ran the 3 scans in on the Guide threat.  MBAM and OTL came up clean.  aswMBR.exe Bsod right after completing, I couldn't save that log.  I ran a second scan which I think is clean.

Given the Bsod I wanted to check if this was due to a Virus or software error.
« Last Edit: August 25, 2012, 05:41:06 PM by Bogartbc »

Bogartbc

  • Guest
Re: Root kit, aswMBR.exe Bsod
« Reply #1 on: August 25, 2012, 05:37:47 PM »
aswMBR.exe logs.  Did you need the MBR.dat?

Bogartbc

  • Guest
Re: Root kit, aswMBR.exe Bsod
« Reply #2 on: August 25, 2012, 06:51:35 PM »
I also have the Bsod dump file if you need it.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: Root kit, aswMBR.exe Bsod
« Reply #3 on: August 25, 2012, 06:58:11 PM »
Quote
Found a root kit yesterday after Cold Booting.  Deleted it with Avast then ran the prompted scan.
what? and where?

Bogartbc

  • Guest
Re: Root kit, aswMBR.exe Bsod
« Reply #4 on: August 25, 2012, 08:36:21 PM »
Unfortunately I have no idea.  Avast popped up saying it found one with no real information displayed.  Delete was auto selected so I continued.  The boot-time scan prompt opened, I accepted and it restarted the system.  I can't find anything in the logs about it, most are dated after the long scan before windows boots and for the scan I ran overnight.  Sorry I didn't think to write what I saw down.
« Last Edit: August 25, 2012, 08:54:32 PM by Bogartbc »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Root kit, aswMBR.exe Bsod
« Reply #5 on: August 25, 2012, 08:48:04 PM »
Are you experiencing any problems at all ?

Bogartbc

  • Guest
Re: Root kit, aswMBR.exe Bsod
« Reply #6 on: August 25, 2012, 08:53:44 PM »
Everything seems fine except I had to disable Web shield for IExplorer or Chrome to connect no matter what I set my firewall to do.  Steam, Xfire and Ventrilo worked fine with Web shield up.  Im just curious due to the aswMBR.exe Bsod and c:\programdata\setwallpaper.cmd which I can not find in Admin mode with folder options showing everything.
« Last Edit: August 25, 2012, 08:57:11 PM by Bogartbc »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Root kit, aswMBR.exe Bsod
« Reply #7 on: August 25, 2012, 09:15:49 PM »
Have you allowed webshield through the firewall ?

Bogartbc

  • Guest
Re: Root kit, aswMBR.exe Bsod
« Reply #8 on: August 25, 2012, 10:25:28 PM »
The scan web (http) traffic was blocking the connect requests, I had to turn it off.  One would open for Avastsvc.exe at boot I would accept then my normal startups that make requests.  Chrome/IE would make one request I would accept but nothing loaded or made another request.  The Web shield doesnt really seem to be scanning anything though.

Im using comodo firewall,  I read on the forum that I should leave Web shield off due to a conflict between these two programs.
« Last Edit: August 25, 2012, 10:29:20 PM by Bogartbc »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Root kit, aswMBR.exe Bsod
« Reply #9 on: August 25, 2012, 10:32:09 PM »
The webshield conflict with Comodo is on the Comodo side, and they want you to reduce protection by disabling Avast...  Personally I would change firewall

Bogartbc

  • Guest
Re: Root kit, aswMBR.exe Bsod
« Reply #10 on: August 25, 2012, 11:04:13 PM »
Do you have any suggestions for a Firewall that works well with Avast?  I've been using Comodo for some long Im not up to date these days.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Root kit, aswMBR.exe Bsod
« Reply #11 on: August 25, 2012, 11:20:19 PM »

Bogartbc

  • Guest
Re: Root kit, aswMBR.exe Bsod
« Reply #12 on: August 26, 2012, 05:50:44 PM »
That seems pretty out of date, 2009.  Are the developers keeping it up to date via an update section similar to Avast?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Root kit, aswMBR.exe Bsod
« Reply #13 on: August 26, 2012, 05:56:00 PM »
No that date refers to when the first programme was added to fileHippo  ;D

Bogartbc

  • Guest
Re: Root kit, aswMBR.exe Bsod
« Reply #14 on: August 26, 2012, 08:26:33 PM »
Im am trying a few workarounds I have found on Comodo's forums to see if anything works.  I have on including the Web shield issue I posted about earlier.  If you have any information on these workarounds please let me know.  Both products I have been happy with the level of control so I'm hesitant to switch either program.


Are the logs I posted clean to you? 

Also is this Bsod a cause of concern?  I do not have the program to read this dump file so I do not know what caused it besides assuming a conflict with the aswMBR scanner.