Author Topic: Rootkit Detection Trojain.Boot.HideMBR.d [FALSE POSITIVE]  (Read 2803 times)

0 Members and 1 Guest are viewing this topic.

YellowFox

  • Guest
Rootkit Detection Trojain.Boot.HideMBR.d [FALSE POSITIVE]
« on: October 04, 2013, 01:46:12 PM »
So today I booted up my computer from hibernation and when it loads I boot up hitman pro and run an early warning scan only expecting to see nothing. Well to cut to the point it's detected a rootkit (More specifically Trojain.Boot.HideMBR.d) and I have no idea of how to deal with this or if it's detecting my computer's Samsung Recovery Solution. Please help ASAP. I already ran TDSSkiller and it couldn't find this.

Fox.
« Last Edit: October 04, 2013, 06:07:44 PM by YellowFox »

YellowFox

  • Guest
Re: Rootkit Detection Trojain.Boot.HideMBR.d
« Reply #1 on: October 04, 2013, 01:48:14 PM »
And this is the TDSSkiller log.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Rootkit Detection Trojain.Boot.HideMBR.d
« Reply #2 on: October 04, 2013, 02:49:14 PM »
You know the drill.

Adwcleaner/MBAM/OTL/ and very important!!! AswMBR if the MbR is infected

http://forum.avast.com/index.php?topic=53253.0
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

YellowFox

  • Guest
Re: Rootkit Detection Trojain.Boot.HideMBR.d
« Reply #3 on: October 04, 2013, 03:09:03 PM »
Here is the MBAR log.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Rootkit Detection Trojain.Boot.HideMBR.d
« Reply #4 on: October 04, 2013, 03:53:44 PM »
Quote
15:38:10.0045 0x14ec  Detected object count: 0
15:38:10.0045 0x14ec  Actual detected object count: 0
15:38:33.0024 0x13c8  Deinitialize success
TDSSKiller (Kaspersky) does not detect it I would trust hitmanpro as far as I could throw it

YellowFox

  • Guest
Re: Rootkit Detection Trojain.Boot.HideMBR.d
« Reply #5 on: October 04, 2013, 03:56:06 PM »
And how much is that?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Rootkit Detection Trojain.Boot.HideMBR.d
« Reply #6 on: October 04, 2013, 03:58:01 PM »
About half an inch :)

YellowFox

  • Guest
Re: Rootkit Detection Trojain.Boot.HideMBR.d
« Reply #7 on: October 04, 2013, 03:59:50 PM »
So you also think it's a False Positive? Also how do you get a computer to run in safe mode without holding down the power button?

YellowFox

  • Guest
Re: Rootkit Detection Trojain.Boot.HideMBR.d
« Reply #8 on: October 04, 2013, 04:18:37 PM »
Here is the OTL log.

HideMbr

  • Guest
Re: Rootkit Detection Trojain.Boot.HideMBR.d
« Reply #9 on: October 04, 2013, 04:26:48 PM »
I also have that message from HitmanPro and i also have Samsung Recovery Solution.. Don't know if we are infected?
« Last Edit: October 04, 2013, 05:23:26 PM by HideMbr »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Rootkit Detection Trojain.Boot.HideMBR.d
« Reply #10 on: October 04, 2013, 05:31:52 PM »
If there are no other indications I would ignore it

YellowFox

  • Guest
Re: Rootkit Detection Trojain.Boot.HideMBR.d
« Reply #11 on: October 04, 2013, 06:04:58 PM »
It's a false positive alright. I just had to use the Samsung Recovery solution (Found out my AV doesn't like safe mode and it broke) and this is waaaay before it appeared and now it's showing. So now thanks to hitman showing me something false I have a few hours of re-updating things. Never using that program again. Thanks for the help Essex glad it was a false showing.

Fox.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Rootkit Detection Trojain.Boot.HideMBR.d [FALSE POSITIVE]
« Reply #12 on: October 04, 2013, 08:41:14 PM »
No problem, but I do find that these "we can find and kill any malware" type programmes very dangerous

YellowFox

  • Guest
Re: Rootkit Detection Trojain.Boot.HideMBR.d [FALSE POSITIVE]
« Reply #13 on: October 04, 2013, 09:14:15 PM »
Indeed from now on I'll just trust my AV.