Results 1 to 9 of 9
  1. #1
    Newbie
    Overall activity: 0%

    Join Date
    Aug 2011
    Location
    Japan
    Posts
    2
    Liked
    0 times
    Points
    514

    MBR.EXE Shows Clean, but RootRepeal Show MBR RootKit Detected on E:

    Hello all I am new to this forum and to rootkits. Pesky sobs.
    I have been reading the forum before posting and trying everything
    everyone else has tried. I just want to be sure before formatting everything that
    I am infected and there is no way to fix.

    MBR.EXE
    Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, no urls but gmer
    Windows 5.1.2600 Disk: WDC_WD3200AAKS-00B3A0 rev.01.03A01 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-5

    device: opened successfully
    user: MBR read successfully
    kernel: MBR read successfully
    user & kernel MBR OK

    RootRepeal
    This seems to long to post here but the top reads:
    Volume E:\ MBR Rootkit Detected!

    Is this normal? Am I infected? What do you need from me
    to continue forward in my fight against rootkits (if any)

    I then downloaded Prevx and it detected "THREAT gnserv.dat-vir in c:\windows\temp\" I bought the license for a year to remove it and after removal and restart and rescan the Threat still shows up.

    Damn the people who make this malicious crap.
    Last edited by DiscoverySound; 08-29-2011 at 03:05 PM. Reason: Adding info

  2. #2
    Tech God
    Overall activity: 0%

    Join Date
    Jan 2008
    Location
    South Africa
    Posts
    1,279
    Liked
    14 times
    Points
    1,853
    You are infected. As it is not easy to get rid of rootkits the question now is how much time and effort are you prepared to spend in trying to get rid of the infection?
    I refuse to tip toe through life only to arrive safely at death

  3. #3
    Newbie
    Overall activity: 0%

    Join Date
    Aug 2011
    Location
    Japan
    Posts
    2
    Liked
    0 times
    Points
    514
    Quote Originally Posted by Odie View Post
    You are infected. As it is not easy to get rid of rootkits the question now is how much time and effort are you prepared to spend in trying to get rid of the infection?
    Well if it will save me the time moving everything to a safe place and re installing everything I would like to give it a shot.

  4. #4
    Tech God
    Overall activity: 0%

    Join Date
    Jan 2008
    Location
    South Africa
    Posts
    1,279
    Liked
    14 times
    Points
    1,853
    In order not to duplicate what you might have done already, could you please tell us which, if any, actions you have taken.

    We might just be lucky in getting rid of it with one of the following scanners

    RootkitBuster (Trendmicro)
    AntiRootkit (Panda)
    Sophos Anti Rootkit (Sophos)

  5. #5
    Verified Member
    Overall activity: 0%

    Join Date
    Aug 2011
    Location
    India
    Posts
    72
    Liked
    13 times
    Points
    1,136
    I would Suggest you to use a Malware removal Tool ComboFix

    ComboFix is a program, created by sUBs, that scans your computer for known malware, and when found, attempts to clean these infections automatically. In addition to being able to remove a large amount of the most common and current malware, ComboFix also displays a report that can be used by trained helpers to remove malware that is not automatically removed by the program.

    Here is the Step by Step Guide on Install / use of ComboFix

    Link : http://www.bleepingcomputer.com/combofix/how-to-use-combofix

  6. #6
    Verified Member
    Overall activity: 10.0%

    Join Date
    Jul 2009
    Posts
    135
    Liked
    1 times
    Points
    3,166
    don't reinstall yet. there's a lot of way to remove the infection of your pc. try malwarebytes and superantispyware.

  7. #7
    Moderator
    Overall activity: 73.0%

    Join Date
    Dec 2008
    Location
    Italy
    Posts
    6,895
    Liked
    1067 times
    Points
    71,755
    Try those free MBR rootkit removal tools, do not forget to read the instructions

    http://www.eset.eu/encyclopaedia/mebroot_backdoor_sinowal_trojan_mebroot_stealth_mbr_trojan_backdoor_maosboot?lng=en

    http://www.symantec.com/security_response/writeup.jsp?docid=2008-020817-4716-99


    http://support.kaspersky.com/faq/?qid=208280684

    http://www.malwarecity.com/blog/free-removal-tool-for-tdl4-available-now-1106.html

    You may also try to use
    NoVirusThanks Anti-Rootkit Free

    I hope it helps
    Roger and out

  8. #8
    Newbie
    Overall activity: 0%

    Join Date
    Aug 2011
    Location
    Ireland
    Posts
    6
    Liked
    3 times
    Points
    462
    DiscoverySound,


    My advice, for what it's worth, is to seek help from a trained analyst on one of the many malware removal forums.

    Some worth mentioning:

    SpywareHammer
    hxxp://spywarehammer.com/simplemachinesforum/index.php?PHPSESSID=tfueabhrg52e60kjpfes0ssa14&board=10.0

    Malware Removal
    hxxp://www.malwareremoval.com/forum/viewforum.php?f=11&sid=86b269a45cfa3b95bf33950c55349b5e

    Aumha Malware Removal
    hxxp://aumha.net/viewforum.php?f=30

    Geeks to Go Virus, Spyware, Malware Removal
    hxxp://www.geekstogo.com/forum/forum/37-virus-spyware-malware-removal/


    ================================

    Sorry about the links, I had to mung them due to posting restrictions for new members. Just replace hxxp with http at the beginning of each link.
    Post denied. New posts are limited by number of URLs it may contain and checked if it doesn't contain forbidden words.

  9. #9
    Experienced User
    Overall activity: 0%

    Join Date
    Sep 2010
    Posts
    848
    Liked
    201 times
    Points
    21,839
    Sometimes rootkit scans are also often a false positive. If you're unsure, do not delete any. MBR is not all bad, could be part of the antivirus or the other. If it all goes normally without any problems on your computer, temporarily ignore. Until you are sure..
    Last edited by solin; 08-31-2011 at 12:45 PM.

 

 

Similar Threads

  1. Replies: 11
    Last Post: 07-16-2011, 09:26 PM
  2. "\Device\mfeavfk01.sys" - clean or infected rootkit?
    By dredge in forum Spyware/Viruses
    Replies: 20
    Last Post: 03-17-2010, 07:13 AM
  3. Clean your junk files in one click with Quick Clean
    By riteshtechie in forum Software
    Replies: 4
    Last Post: 03-05-2010, 04:08 AM
  4. Moniter not detected
    By shan in forum Linux
    Replies: 1
    Last Post: 11-02-2009, 07:49 PM
  5. 1Gb Ram detected but 512mb not.
    By assassin in forum Hardware
    Replies: 4
    Last Post: 09-02-2009, 02:16 PM
All times are GMT +8. The time now is 09:56 AM.