Author Topic: Avast doesn't detect win32/mebroot.h trojan  (Read 11477 times)

0 Members and 1 Guest are viewing this topic.

meck

  • Guest
Avast doesn't detect win32/mebroot.h trojan
« on: July 11, 2008, 05:28:00 PM »
Hi all,
  i used my pendrive in a pc with other antivirus and this detected win32/mebroot.h trojan. Is a MBR trojan (?). Why did not avast detect it?

 Thanks \o
« Last Edit: July 11, 2008, 07:42:00 PM by meck »

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Avast doesn't detect win32/mebroot.h trojan
« Reply #1 on: July 11, 2008, 09:01:21 PM »
Difficult to say... but is it detected within a file or just the MBR?
Maybe you haven't a file to send to avast for analysis...
The best things in life are free.

meck

  • Guest
Re: Avast doesn't detect win32/mebroot.h trojan
« Reply #2 on: July 12, 2008, 08:50:12 AM »
Hi Tech,

Just MBR.

Reading others forums i saw a possible solution using mbr.exe from http://www.gmer.net. But in my computer doesn't work. Could i send a file using mbr.exe?

Stealth MBR rootkit detector 0.2.4 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
malicious code @ sector 0x12a14c00 size 0x194 !

Thanks \o
« Last Edit: July 12, 2008, 09:08:51 AM by meck »

meck

  • Guest
Re: Avast doesn't detect win32/mebroot.h trojan
« Reply #3 on: July 12, 2008, 10:04:45 AM »
Hi, i am going to reinstall windows.

Thanks \o

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Avast doesn't detect win32/mebroot.h trojan
« Reply #4 on: July 12, 2008, 03:10:58 PM »
Could i send a file using mbr.exe?
GMER now belongs to Alwil as the same as avast.
I don't think mbr.exe will send/collect any information.

Hi, i am going to reinstall windows.
There are some ways to fix mbr before reinstalling Windows... ::)
The best things in life are free.

meck

  • Guest
Re: Avast doesn't detect win32/mebroot.h trojan
« Reply #5 on: July 12, 2008, 03:23:41 PM »
Could i send a file using mbr.exe?
GMER now belongs to Alwil as the same as avast.
I don't think mbr.exe will send/collect any information.

Hi, i am going to reinstall windows.
There are some ways to fix mbr before reinstalling Windows... ::)

 :)

Well how can i do that?, I have used fixmbr from "recuperation console" Recovery Console,  but mbr.exe shows the same message:
Stealth MBR rootkit detector 0.2.4 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
malicious code @ sector 0x12a14c00 size 0x194 !
« Last Edit: July 13, 2008, 09:26:21 AM by meck »

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Avast doesn't detect win32/mebroot.h trojan
« Reply #6 on: July 12, 2008, 04:04:57 PM »
Well how can i do that?, I have used fixmbr from "recuperation console"
One way to do so. Even following this way can't you boot?
Why do you think that now your MBR is corrupt?
The best things in life are free.

meck

  • Guest
Re: Avast doesn't detect win32/mebroot.h trojan
« Reply #7 on: July 13, 2008, 01:11:14 AM »
Because mbr.exe is showing the message: malicious code @ sector 0x12a14c00 size 0x194 !

\o

wyrmrider

  • Guest
Re: Avast doesn't detect win32/mebroot.h trojan
« Reply #8 on: July 13, 2008, 01:45:50 AM »
google gives some interesting threads on your hits

http://www.wilderssecurity.com/archive/index.php/t-211133.html

meck

  • Guest
Re: Avast doesn't detect win32/mebroot.h trojan
« Reply #9 on: July 13, 2008, 09:38:57 AM »
Using gmer.exe (mbr.exe) version 1.0 copied these sector to a file and when was writing it, Avast antivirus detected it like Win32:MBRoot-B [Rtk] !! :)


Thanks wyrmrider \o

meck

  • Guest
Re: Avast doesn't detect win32/mebroot.h trojan
« Reply #10 on: July 13, 2008, 09:39:25 AM »
I am going to use fixboot like say at http://www.wilderssecurity.com/archive/index.php/t-211133.html

Not works!, The bad bug doesn't want to go.. :(
« Last Edit: July 13, 2008, 09:51:05 AM by meck »

wyrmrider

  • Guest
Re: Avast doesn't detect win32/mebroot.h trojan
« Reply #11 on: July 14, 2008, 12:36:10 AM »
there is a boot fix on the ANTIVIR website under "programs"
no idea if it is any different
did you try a "scan on boot" option with Avast?
perhaps someone with experience with this baddie will show up Monday
did you get the file copied?
if so submit to "Virus Total" and to Avast

meck

  • Guest
Re: Avast doesn't detect win32/mebroot.h trojan
« Reply #12 on: July 15, 2008, 12:54:08 AM »

wyrmrider

  • Guest
Re: Avast doesn't detect win32/mebroot.h trojan
« Reply #13 on: July 15, 2008, 02:08:01 AM »
someone much older and wiser than I may have an answer coming
but the next thing I would do would be to post in the Virus and Worms Forum- scroll down
give a link to this thread
you might ask that since this is a trojan if you should be in a antimalware forum

Sunbelt found it
so a download and scan with Counterspy free try and a post in the sunbelt forum might work if nothing else pops up here
also Trojan Hunter is worth a shot
A-squared but watch for FP's on ALL of these

A lot of scanners like DrWeb and Kaspersky which is usually good with trojans did  not give hits
IS there still a DOS boot scanner around
AVG used to have one
puts thinking cap on

I am concerned about the .gen which usually means a heuristic hit and not a proven positive
wadda you think?

meck

  • Guest
Re: Avast doesn't detect win32/mebroot.h trojan
« Reply #14 on: July 15, 2008, 09:34:41 AM »
Ooops, sorry :/