Hi, my avast free antivirus 6.0.100 advice me about a:" \.\PHYSICALDRIVE…:MBROOT " on logon, I’m reading more solution in this forum too, downloaded aswMBR.exe and everythings like this post: " http://forum.avast.com/index.php?topic=71782.0 "
but virus or rootkit stay always there… the log of aswMBR after FixMBR is:
aswMBR version 0.9.4 Copyright(c) 2011 AVAST Software
Run date: 2011-04-15 16:15:48
16:15:48.280 OS Version: Windows 5.1.2600 Service Pack 3
16:15:48.280 Number of processors: 1 586 0x701
16:15:48.280 ComputerName: ANGEL UserName:
16:15:49.592 Initialize success
16:15:54.109 Disk 0 (boot) \Device\Harddisk0\DR0 → \Device\Ide\IdeDeviceP0T0L0-4
16:15:54.129 Disk 0 Vendor: Maxtor_4D040H2 DAK019K0 Size: 39083MB BusType: 3
16:15:54.129 Disk 1 \Device\Harddisk1\DR1 → \Device\Ide\IdeDeviceP0T1L0-c
16:15:54.139 Disk 1 Vendor: Maxtor_4D040H2 DAH017K0 Size: 39083MB BusType: 3
16:15:56.172 Disk 0 MBR read successfully
16:15:56.172 Disk 0 MBR scan
16:15:58.185 Disk 0 scanning sectors +80035830
16:15:58.225 Disk 0 malicious Win32:MBRoot code @ sector 80035833 !
16:15:58.225 Disk 0 PE file @ sector 80035855 !
16:15:58.235 Disk 0 scanning C:\WINDOWS\system32\drivers
16:16:14.818 Service scanning
16:16:44.671 Disk 0 trace - called modules:
16:16:44.711 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll viaidexp.sys
16:16:44.721 1 nt!IofCallDriver → \Device\Harddisk0\DR0[0x81b54030]
16:16:44.802 3 CLASSPNP.SYS[f9568fd7] → nt!IofCallDriver → \Device\Ide\IdeDeviceP0T0L0-4[0x81b09030]
16:16:44.802 Scan finished successfully
[*]Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
[*]Double click on ComboFix.exe & follow the prompts.
[*]As part of it’s process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it’s strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
[*]Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it’s malware removal procedures.
No, there was firewall with close ports, but i think settings out for the virus, now the firewall was down, however the pc is without adsl so…, windows mystery… yes the disk 1 is bootable; Ok for cleaning it what can i do?
Sorry always the same logs, I see it carefully…
However Avast doesn’t advice about virus \.\PHYSICALDRIVE0 - but aswMBR advice it…
Thanks for the fix and the time that you spend with my problem, excuse my bad english isn’t my language.
I think that I have to get used to live with this virus XD
Regards
Yes, I’ve just done it with no result or the same log of the before device… I had the problem on deactivation of avast startup and l’ll reinstall it. I’m sorry but I’m on another pc at this time, I can’t put in this post the log, however is the same of the first.
Hi I have just re-read the logs and what ASWMbr is showing is a backup but inactive copy of the bootkit - At the moment the only way to remove it is to reformat the drive. However, it is inactive
GMER is working on a way to remove this backup copy, but as yet does not have a viable removal cure