Hey guys,
Another one for you.
Hopefully I have followed the post guide properly below. First time poster. Yesterday, I was simply watching youtube on Firefox when all of a sudden all desktop icons disapeared, sound drivers halted, and page changed to “Avast Enhanced Protection”. Suspected was not right so Ctrl+Alt+Del Firefox, removed my ethernet cable and unplugged my two external drives. After doing this a load of windows popped up informing me my “hard-drive clusters” were damaged [as if!] and that all my files were locked.
I maintain a scorched earth policy generally and decided I’d just format it as I’d recently backed up last month when buying my new video card. FORMATTED WIN7 and reinstalled entire OS [I think I may not have cleared the 100mb partition] and reinstalled my main programs from internet. About half an hour after reinstalling I get a warning from AVAST stating I have rootkit MBR:Alureon infection. I have scanned PC and submit to you results below. Please bear in mind this is a fresh Win7 install and it is still updating windows in the background as we speak.
Thanks in advance,
Mike
Malwarebytes Anti-Malware (Trial) 1.60.1.1000
www.malwarebytes.org
Database version: v2012.03.30.07
Windows 7 x64 NTFS
Internet Explorer 9.0.8112.16421
Mike :: MIKE-PC [administrator]
Protection: Enabled
30/03/2012 19:47:35
mbam-log-2012-03-30 (19-47-35).txt
Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 451412
Time elapsed: 1 hour(s), 28 minute(s), 3 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 1
F:\Backup\Original Backup\PPC\vba\gsgetfile.dll (Trojan.Dropper) → Quarantined and deleted successfully.
(end)
Restarting PC and will continue with follow up required posts.
update [if your reCaptcha post system visual tests will actually let me post. Some are just white noise of actual images instead of words !?!]
http://i7.photobucket.com/albums/y286/the__jin/rootkit.png
Screenshot and two logs.