Author Topic: aswMbr.exe finds Win32:Aluroot-B but does not fix.  (Read 2874 times)

0 Members and 1 Guest are viewing this topic.

Farms619

  • Guest
aswMbr.exe finds Win32:Aluroot-B but does not fix.
« on: May 11, 2013, 07:19:13 AM »
Hello
I have scanned for viruses with several legitimate scanners including the ones listed by you guys and have come up clean on most except for aswMBR.exe. This one keeps detecting Win32:Aluroot-B in "windows\system32\csrsrv.dll", but will not fix it. My computer is not displaying any noticeable symptoms of an infection. I have attached the requested reports. Help?.

Offline mikaelrask

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1556
Re: aswMbr.exe finds Win32:Aluroot-B but does not fix.
« Reply #1 on: May 11, 2013, 08:32:02 AM »
hey and welcome to the forum.

a malware expert will help you from here when one is online later today.
Windows 8.1 amd a10-5700 64 bit
12 GB ram 1 tb hard drive. Avast 18, MBAM

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: aswMbr.exe finds Win32:Aluroot-B but does not fix.
« Reply #2 on: May 11, 2013, 12:08:25 PM »
Hi I believe that may be a false positive, is it only AswMBR that is reporting it ?

Download the latest version of TDSSKiller from here and save it to your Desktop.
 
 
  • Doubleclick on TDSSKiller.exe to run the application


  • Then click on Change parameters.
     

     
  • Check the boxes beside Verify Driver Digital Signature and Detect TDLFS file system, then click OK.
     
  • Click the Start Scan button.
     
     
  • If a suspicious object is detected, the default action will be Skip, click on Continue.
     

     
  • If malicious objects are found, they will show in the Scan results and offer three (3) options.
  • Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.

  • Get the report by selecting Reports

 
  • Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.
Please copy and paste its contents on your next reply.

Farms619

  • Guest
Re: aswMbr.exe finds Win32:Aluroot-B but does not fix.
« Reply #3 on: May 11, 2013, 01:00:52 PM »
Hi
Yes, it is only aswMBR.exe reporting it.
I attempted to paste in the TDSSKiller report, but it exceeds the character limit, I have attached it instead.
Thanks

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: aswMbr.exe finds Win32:Aluroot-B but does not fix.
« Reply #4 on: May 11, 2013, 01:27:44 PM »
OK you are the second one to show this file in aswmbr, in both cases it is the only programme reporting it

I believe this to be a false positive, does a standard Avast scan find it ?

Farms619

  • Guest
Re: aswMbr.exe finds Win32:Aluroot-B but does not fix.
« Reply #5 on: May 11, 2013, 01:34:38 PM »
A standard avast scan reports no threats, and I ran a boot time scan yesterday with the same result.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: aswMbr.exe finds Win32:Aluroot-B but does not fix.
« Reply #6 on: May 11, 2013, 03:13:20 PM »
I think it is a FP I will pass it on to GMER