Hello!I read this topic, i have the same problem... i think my pc is infected with Mebroot!!!I use nod- eset smart security antivir. and detected a treath in sector of 1 physical disk-Win 32/Mebroot.K trojan (error while cleaning- operration unaviable for this object type).
I run XP, sp2 in my computer.I make a scan with MBR rootkit detector and the log say:
Stealth MBR rootkit detector 0.2.4 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
malicious code @ sector 0xdf937c1 size 0x1ac !
copy of MBR has been found in sector 62 !"
I make a scan with GMER and in Malware section found written in black:
Disk: \Device\Harddisk0\DR0 value: sector 61 : malicios code @sector 0xdf937c1 size 0x1ac and
Disk: \Device\Harddisk0\DR0 value: sector 62 : copy of MBR
I also perform a scan with Fix Mebroot (removal tool from symantec) and say mebroot was not found in my system with this log:
"Symantec Trojan.Mebroot Removal Tool 1.0.1
Found drive \\.\PhysicalDrive0, analyzing MBR...
Found drive \\.\PhysicalDrive1, analyzing MBR...
Creating FixMebroot service driver
Trojan.Mebroot has not been found active on your computer.
Delete service driver
Delete driver file
The tool initiated a system reboot."
I also make a scan with spyboot S&D and my system is clean.I don't know what can i do and what to believe.Please give me an advice what can i do in this situation!Thank you!
Edit: I escape from this malaware with Cure it program!Found it, cure it! My log files on nod, gmer are ok now!Thank you!
Edited by sermonize, 07 November 2008 - 11:29 AM.