Author Topic: MBR Hurri Rootkit Found  (Read 1918 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
MBR Hurri Rootkit Found
« on: November 19, 2017, 11:05:59 AM »
Whenever I start my computer avast warns me of a Hurri rootkit in  MBR:\\.\PHYSICALDRIVE0 and recommends that I delete it which I do. Then it recommends to run a boot scan and restarts my computer, in the boot scan it detects the same rootkit but when I select Delete (or anything other than Ignore or Ignore All) it says Action Not Implemented. Because of which I have to select Ignore and let the scan continue. After the computer boots again I get the same warning message.
As recommended here (https://forum.avast.com/index.php?topic=134584.0) I am attaching 2 of 3 log files for Gmer (the second log file is 4.6MB) if that helps at all.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: MBR Hurri Rootkit Found
« Reply #1 on: November 19, 2017, 11:38:14 AM »
Attach your basic diagnostic logs. (MBAM and FRST)
Instructions: https://forum.avast.com/index.php?topic=194892
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: MBR Hurri Rootkit Found
« Reply #2 on: November 19, 2017, 04:55:29 PM »
I scanned using Malwarebytes (I had done this before but it didn't detect anything because I hadn't selected scan for rootkits) and it detected the rootkits and was able to delete them.
The rootkit no longer seems to be on my computer.
I am attaching the log file before and after removing the rootkits just in case.

REDACTED

  • Guest
Re: MBR Hurri Rootkit Found
« Reply #3 on: November 19, 2017, 04:56:34 PM »
Sorry forgot to add the log files.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: MBR Hurri Rootkit Found
« Reply #4 on: November 20, 2017, 04:43:05 PM »
FRST is the really important one. I would also run aswMBR and post that report here too...

http://public.avast.com/~gmerek/aswMBR.htm

edit:
.... huh?
Code: [Select]

Threats Detected: 2
Threats Quarantined: 0
Code: [Select]
Bootkit.Malmo.MBR, 0, No Action By User, [16479], [200000073],0.0.0
Bootkit.Malmo.MBR, 2, No Action By User, [16479], [200000073],0.0.0
« Last Edit: November 20, 2017, 04:44:50 PM by Michael (alan1998) »
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.