Author Topic: Help! Win64 Alureon B@mbr Rootkit Re-occurs: MBAM and OTS Logs in thread  (Read 8774 times)

0 Members and 1 Guest are viewing this topic.

mr_glide

  • Guest
Hi all,

First post here, and what a doozy of a virus my brand new system has picked up - the Win64 Alureon B@mbr. It seemed to have been gotten rid of by Avast (although in Safe Mode, I had to just delete it, as when I selected the Move to Chest option, it wouldn't start up - might this be to do with the fact that it appears to be running in demo in Safe Mode, even though I renewed my licence recently?), and I used MBAM and OTP afterwards to see if anything was turned up, but looking at these threads, I was just waiting for it re-occur...I turn my PC on this morning, and it has.

I've currently sitting in Safe Mode. Slightly worryingly, MBAM turns up nothing (and I've no idea how to read OTP's results  ;) ). Avast, however, has now picked up a new variant: Win64:Alureon-C [Trj] . I tried moving it to the virus chest, but as last time, got this message: Virus Chest Server not running. RPC communication failed. Even thought I've deleted it again, I suspect a new variant will be back soon, and so on and so on. Dear me, what a mess.

I'm a newcomer to dealing with malware, so let me know if I've neglected to mention anything obvious! I've attached the log from MBAM, but the OTS one proved to be too big, so here it is linked from my own webspace: http://nickparton.co.uk/misc/

Cheers,

Nick

Offline mikaelrask

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1556
welcome to the forum. lets hope someone check your log there I'm no expert on them.
but i could recommend you to do a boot scan sens you report avast is detected malware but unable to do anything with them.

http://www.schmahl.net/avastbootscan.php

then meaby a scan with superantispyware could work as a second opion.

http://www.superantispyware.com/

good luck and let us know on the progress.

Windows 8.1 amd a10-5700 64 bit
12 GB ram 1 tb hard drive. Avast 18, MBAM

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37553
  • Not a avast user
The log you saved  ( linked to ) is saved in Unicode so it looks like chines gibbely gobbel, you need to save it in ANSI

mr_glide

  • Guest
@mikaelrask - hiya, and cheers for the advice. Don't know why I didn't think of the boot scan! Duh.

The log you saved  ( linked to ) is saved in Unicode so it looks like chines gibbely gobbel, you need to save it in ANSI

Aha, I see - thanks for the heads-up. I resaved it out as ANSI, so I hope that will do the job.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Hi you have Avast 4.8 and that is not man enough for the MBR variants.  So an upgrade to V6 is highly recommended

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it


Click the "Scan" button to start scan


On completion of the scan click save log, save it to your desktop and post in your next reply

mr_glide

  • Guest
Hi you have Avast 4.8 and that is not man enough for the MBR variants.  So an upgrade to V6 is highly recommended

Download aswMBR.exe ( 511KB ) to your desktop.


On completion of the scan click save log, save it to your desktop and post in your next reply


Hi,thanks for the reply and help - this is definitely not my area of expertise! I ran MBR, and the scan results are attached.

Also, I only paid for renewal of my licence in January this year, and V6 came out in Feb - is the upgrade free, or not? Slightly confused...

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Also, I only paid for renewal of my licence in January this year, and V6 came out in Feb - is the upgrade free, or not? Slightly confused...

Yes, it's free. :)
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

mr_glide

  • Guest

Also, I only paid for renewal of my licence in January this year, and V6 came out in Feb - is the upgrade free, or not? Slightly confused...

Whoops, forget that last bit - I forgot to install the licence renewal update, and now I have, it's given me Avast 6.0.1000! Hurrah and all that  :)

mr_glide

  • Guest
Also, I only paid for renewal of my licence in January this year, and V6 came out in Feb - is the upgrade free, or not? Slightly confused...

Yes, it's free. :)
asyn


Cheers, looks like I found out just at the right time!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<

Also, I only paid for renewal of my licence in January this year, and V6 came out in Feb - is the upgrade free, or not? Slightly confused...

Whoops, forget that last bit - I forgot to install the licence renewal update, and now I have, it's given me Avast 6.0.1000! Hurrah and all that  :)

Hurrah. ;)
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
OK lets give GMERS tool a run at this


Re-Run aswMBR

Click Scan

On completion of the scan

Click the   Fix    Button


Save the log as before and post in your next reply
« Last Edit: March 11, 2011, 02:53:32 PM by essexboy »

mr_glide

  • Guest
OK lets give GMERS tool a run at this


Well, I've run MBA, and am back in normal startup without a bluescreen yet, so it looks hopeful! Log attached...

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
That looks good - I will need just one more ASWMbr scan to confirm that you are clear....  Any other problems ?

mr_glide

  • Guest
That looks good - I will need just one more ASWMbr scan to confirm that you are clear....  Any other problems ?

Not so far - been running through the range of apps I have, and nothing's gone awry yet. Fingers crossed it stays that way!

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
OK lets call you fixed

Run OTS and hit the cleanup button - poof its gone  ;D

Delete aswmbr from the desktop along with the logs

OTS showed no other malware