n.exn, trojan virus Do not know how to remove
#31
Posted 23 February 2010 - 03:15 PM
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
PE file found in sector at 0x01749DDC1 !
I ran Root Repeal, following all the instructions you listed, but after a few minutes of scanning, an error message would appear stating "Could not read the boot sector. Try adjusting the Disk Access Level in the Options dialog." The program would stop responding after this message appeared, so while I wasn't able to scroll down to see all of the results up to that point, there was a message visible that said a rootkit was found in J:. I ran the program twice, but received the same error message both times. I didnt want to adjust any of the disk level access options without speaking with you first.
Also, I have 142gb free (out of a total of 181gb) on my C: drive.
#32
Posted 24 February 2010 - 07:56 AM
Post me the screenshot of all prompt please
#33
Posted 24 February 2010 - 12:50 PM
#34
Posted 25 February 2010 - 08:09 AM
Then, go to the "Volume J:\" which says "MBR Rootkit Detected" and right click on it.. Then choose "Wipe File".. Do the same for each file that says "MBR Rootkit Detected".. Then reboot the computer and scan your external drives again with RootRepeal.. Then tell me how it goes
#35
Posted 25 February 2010 - 12:41 PM
1- Is there any risk in transferring the files from my externals onto my C: drive of infecting the C: drive? I'm assuming there isn't as the malware seems to reside in the MBR of the externals as opposed to any individual files themselves, but I just want to confirm this with you so i dont end up in the same situation I was in a week or two ago.
2- Also, I'm not sure exaclty where to find the option "Wipe File". If you mean RootRepeal offers this then I don't think it will work as the program stalls after that error message pops up and I am unable to interact with it at all. In the picture that I just posted I am able to close the error message window, but the main window to RootRepeal is no longer responding as I cant click on any of the entries (including the one for J: stating it is infected) nor can I scroll down to see what other drives may be infected with a rootkit. I have to use Task Manager to close the program as I am unable to click the "X" in the upper right corner of the window. Perhaps if I changed the disk access levels in the RootRepeal options then the error wouldn't appear and the program may not hang, but I am wary of messing with options that can have a potentially negative impact without the advice of expert like yourself. To make things a bit clearer for you I am going to type out the 4 different disk access levels the options menu offers along with the attributes for each level. I think that if I could change this to allow the scan to successfully complete then I could perform the "wipe file" you instructed me to do.
Lowest Level- Only supports SCSI devices. Does not support dynamic disks.
Special Level- Supports all block-based devices. Does not support dynamic disks.
Middle Level- Supports all block-based devices. Does not support dynamic disks.
High level- Supports all devices. Supports dynamic disks.
Thanks!
#36
Posted 25 February 2010 - 08:19 PM
There's always risk on everything that we do, but don't worry too much.. The most important thing is you backup all your data.. We can clean your computer or in worst case scenario just reformat it, but if you lost your data, it would be very difficult to recover it back..
And please use the "High Level" first.. Then if unsuccessfull, followed with the Middle >> Special >> Lowest level.. But only do this after backup all your data
#37
Posted 27 February 2010 - 06:31 PM
Attached File(s)
-
rootrepeal.txt (54.64K)
Number of downloads: 11
#38
Posted 02 March 2010 - 05:34 AM
Status: MBR Rootkit Detected!
Path: Volume K:\
Status: MBR Rootkit Detected!
Path: Volume L:\
Status: MBR Rootkit Detected!
Lets just "Wipe File" to those things and see if it will take care of it..
#39
Posted 05 March 2010 - 04:13 PM
#40
Posted 06 March 2010 - 12:46 AM
Status: MBR Rootkit Detected!
Path: Volume K:\
Status: MBR Rootkit Detected!
Path: Volume L:\
Status: MBR Rootkit Detected!
#41
Posted 06 March 2010 - 10:50 PM
#42
Posted 07 March 2010 - 06:49 AM
#43
Posted 07 March 2010 - 02:29 PM
#44
Posted 08 March 2010 - 07:19 AM
Go to below link and download MBRFix
http://www.sysint.no/en/Download.aspx
Save and unzip them to your Desktop.. Then open the mbrfix folder, copy both mbrfix.exe and mbrfix64.exe to your root J, K, and L drive..
Then go to Start >> Run >> copy/paste below >> Enter
J:\MbrFix.exe /drive 0 fixmbr /yes
K:\MbrFix.exe /drive 0 fixmbr /yes
L:\MbrFix.exe /drive 0 fixmbr /yes
Reboot your computer and run Avira/RootRepeal (only one) again and tell me how it goes
This post has been edited by fenzodahl512: 08 March 2010 - 07:20 AM
#45
Posted 08 March 2010 - 12:58 PM

Help


Back to top










