Author Topic: [RESOLVED] Rootkit infection detected... :(  (Read 14546 times)

0 Members and 1 Guest are viewing this topic.

Offline pk

  • Avast team
  • Super Poster
  • *
  • Posts: 2078
Re: Rootkit infection detected... :(
« Reply #15 on: February 02, 2011, 03:54:32 PM »
I have two disks, but aswMBR shows the same size for both HDDs:

14:49:56.660    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP3T0L0-6
14:49:56.660    Disk 0 Vendor: INTEL_SSDSA2M160G2GC 2CV102HD Size: 152627MB BusType: 11
14:49:56.663    Disk 1  \Device\Harddisk1\DR2 -> \Device\000000c9
14:49:56.666    Disk 1 Vendor: WD______ 1.75 Size: 152627MB BusType: 7


Offline gmer

  • Avast team
  • Jr. Member
  • *
  • Posts: 35
  • The rootkit guy
Re: Rootkit infection detected... :(
« Reply #16 on: February 02, 2011, 05:06:03 PM »
Thanks Petr, it indeed for all disks shows boot disk size.

Fixed, new version uploaded.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Rootkit infection detected... :(
« Reply #17 on: February 02, 2011, 07:37:10 PM »
Ok and thanks - trying it now on one here that MBRCheck has failed on

Offline pk

  • Avast team
  • Super Poster
  • *
  • Posts: 2078
Re: Rootkit infection detected... :(
« Reply #18 on: February 02, 2011, 08:57:18 PM »
Should it scan MBR on all available HDDs? It seems, it scans only Disk 0.
Timestamp is not local, but in GMT.

Offline gmer

  • Avast team
  • Jr. Member
  • *
  • Posts: 35
  • The rootkit guy
Re: Rootkit infection detected... :(
« Reply #19 on: February 02, 2011, 09:05:34 PM »
It scans boot disk (in most cases its number is 0)


Offline pk

  • Avast team
  • Super Poster
  • *
  • Posts: 2078
Re: Rootkit infection detected... :(
« Reply #20 on: February 02, 2011, 09:07:40 PM »
It scans boot disk (in most cases its number is 0)

So is this log ok? What about Disk 1?



aswMBR version 0.9 Copyright(c) 2010 avast! Software
Run date: 2011-02-02 14:49:54
-----------------------------
14:49:54.256    OS Version: Windows 6.1.7600
14:49:54.256    Number of processors: 2 586 0x1706
14:49:54.258    ComputerName: PK-PC  UserName:
14:49:54.783    Initialize success
14:49:56.660    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP3T0L0-6
14:49:56.660    Disk 0 Vendor: INTEL_SSDSA2M160G2GC 2CV102HD Size: 152627MB BusType: 11
14:49:56.663    Disk 1  \Device\Harddisk1\DR2 -> \Device\000000c9
14:49:56.666    Disk 1 Vendor: WD______ 1.75 Size: 152627MB BusType: 7
14:49:56.671    Disk 0 MBR read successfully
14:49:56.672    Disk 0 scanning MBR
14:49:56.679    Disk 0 scanning sectors +312578048
14:49:56.682    Disk 0 scanning C:\Windows\system32\drivers
14:49:57.687    Scan finished successfully

TheSecurityFreak

  • Guest
Re: Rootkit infection detected... :(
« Reply #21 on: February 02, 2011, 11:31:51 PM »
Deleting that file (it looks like it's the MBR) might harm your system.

Try Dr.Web CureIt, and see if that detects it and fixes it (It probably won't delete the MBR completely)

Pony_Girl

  • Guest
Re: Rootkit infection detected... :(
« Reply #22 on: February 03, 2011, 01:50:26 AM »
Please send your aswAr.log file to: gmerek(at)avast.com

Done as requested. =)

Pony_Girl

  • Guest
Re: Rootkit infection detected... :(
« Reply #23 on: February 04, 2011, 02:08:06 AM »
Oh for f**ksake... I have had it up to here with my 18 y/o younger brother... gmer, I got your e-mail, tried to download the file to my desktop as instructed to do so, but I couldn't do that without some password...
Wanna know why? Because my bro' kept downloading dodgy crap and getting viruses, so my mum made it so everybody has to use a password (that only she knows) in order to download anything, except that was a pretty pointless idea as she let my bro' know the password anyway (because it's easier for her just to let him do whatever the f**k he likes instead of telling him "No!") *facepalm X100*, it would be absolutely pointless me trying to explain that I need it to get rid of this bloody rootkit as she's pretty much computer illiterate *faceplams again, thinking about tearing hair out* and it'd all go over her head... As soon as I've saved enough, I'm getting my own computer, if my bro' gets within a meter of it I'll chase him with a stick to keep him away so he can't break it, because I don't have money to keep buying new computers and doubtless I'd have to if he  got anywhere near it. Had it up to here with fools who think they know everything (bro'), clueless people (mum) and sharing a damned comuter. Rant over, for real, no more ranting, just felt like ranting... *Weary sigh...*

Back to topic: Forgot to mention this - got a re-direct virus, from what I've garnered it's probably something to do with the rootkit (actually, this apparent "re-direct" virus thing doesn't seem to do much, and when it does it just takes me off to some apparently harmless but extremely dull sites about car insurance and dieting, if it does try to take me to an apparently "Harmful" site, it just gets blocked before it can load resulting in FAIL *shrug*. Still want rid of it though, don't want it possibly doing other things).
« Last Edit: February 14, 2011, 11:52:17 PM by Pony_Girl »

ArtemisF0wl

  • Guest
Re: Rootkit infection detected... :(
« Reply #24 on: February 04, 2011, 03:09:50 AM »
The password is for browsers only, or the whole system? For instance, i was thinking maybe you and GMER could transfer the file via ICQ or some messenger; even email (the file is tiny). Just a thought, i'd like to see you toast this little nasty. ;)
« Last Edit: February 04, 2011, 03:11:34 AM by ArtemisF0wl »

Pony_Girl

  • Guest
Re: Rootkit infection detected... :(
« Reply #25 on: February 04, 2011, 10:16:40 PM »
@ ArtemisF0wl: I have no idea what the password covers, aside from that it's needed to download ANYTHING at all. But never mind that, I've aquired the useless stupid f**king password.

@ gmer: Followed your instructions exactly. Except, when I went to click "Save" I noticed it had a "Fix" button too, I didn't touch that though because I thought it best to just do as I was told. Should I have clicked "Fix"? By the way, not sent the files yet as despite the amount of searching I've done (this is something I'm pretty familiar with) I just can't find the f**ker ANYWHERE (there are also folders/files that for some reason I DON'T have access too/permision to open/look at, how helpful is that (sarcasm)... *growls*)...

By the end of February I may actually have torn my hair out in frustration and smashed the computer to pieces in a fit of rage. I hate technology when it doesn't work/do what it's meant to do (and my irresponsible thinks he knows everything but actually knows f**k all brother), I'd rather go back to living under a rock, I was quite happy there before. End of 2009 up until today has just been horendous and extremely irritating in all aspects, so if one more thing goes wrong I may actually go insane. Rant over.

Pony_Girl

  • Guest
Re: Rootkit infection detected... :(
« Reply #26 on: February 04, 2011, 10:26:10 PM »
At this rate I may just haul the damned computer to a person who is qualified to fix it and paid to do so, and offer a large sum of cash in hand to take the back seat and say "Here's the cash, YOU deal with it!"... *Weary sigh*.

Pony_Girl

  • Guest
Re: Rootkit infection detected... :(
« Reply #27 on: February 04, 2011, 11:29:26 PM »
Actually, just a thought - but is it at all possible to just remove and replace some sort of part of the computer to get rid of the nasty rootkit thing? Because if it is I'll fork out whatever price is asked to replace it. Thanks for your time.

Pony_Girl

  • Guest
Re: Rootkit infection detected... :(
« Reply #28 on: February 06, 2011, 02:42:04 AM »
*Shameless bump*

@ gmer: Followed your instructions to a T, however was unable to send the requested files (aswMBR.log and MBR.dat) as despite the amount of searching I've done I just can't find where they're located.

So, anybody know where the files/folders aswMBR.log and MBR.dat are located/where I should look?

ArtemisF0wl

  • Guest
Re: Rootkit infection detected... :(
« Reply #29 on: February 06, 2011, 03:07:32 AM »
click "start" and type in the search box  aswMBR.txt, and do the same for the other file. hope this helps