Author Topic: HELP !!! for "aswmbr.exe" & File: C:\Windows\system32\csrsrv.dll **INFECTED** W  (Read 1542 times)

0 Members and 1 Guest are viewing this topic.

Offline 46926065

  • Newbie
  • *
  • Posts: 1
HELP !!!

The original file location is  "C:\Windows\System32\csrsrv.dll ". - The virus can be scanned & found but cannot be cleaned by tool of “aswmbr.exe”  earlier. But now if run "aswmbr.exe" then pc bluescreen & restart automatically everytime.    Pls help to solve it & feedback. Thanks!

"08:10:36.394    AVAST engine scan C:\Windows
08:11:15.623    AVAST engine scan C:\Windows\system32
08:12:45.271    File: C:\Windows\system32\csrsrv.dll  **INFECTED** Win32:Aluroot-B [Rtk]"--   It can be scanned & found but cannot be cleaned by tool of “aswmbr.exe”  earlier. But now if run "aswmbr.exe" then pc bluescreen & restart automatically everytime.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Attach your basic diagnostic logs. (MBAM and FRST)
Instructions: https://forum.avast.com/index.php?topic=194892
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Sorry Asyn to barge in,

Attach the aswMBR log as well as run a Rootkit scan from Malwarebytes.

https://www.malwarebytes.com/antirootkit/
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
aswMBR is an outdated tool and it is not safe to use plus tool is mainly design for mbr based rootkits.
Quote
08:12:45.271    File: C:\Windows\system32\csrsrv.dll  **INFECTED** Win32:Aluroot-B [Rtk]"--
...is most likely a FP. Not malware related issue.

To chech for Rootkit use Malwarebytes with "Scan for rootkits" option enabled or you may use MBAR, but do NOT use aswMBR.
https://www.malwarebytes.com/antirootkit/


« Last Edit: January 03, 2020, 03:54:52 PM by magna86 »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Side note, the functionality has been included in the AV.
As mentioned above, the standalone product is outdated.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0