Wednesday, April 20, 2011

PhysicalDrive0: Win32:MBRoot removed by using TDSSKiller

.: MBR problem? Master Boot Record?

"A suspicious hidden object (rootkit) has been detected on your system. This may be a sign of a malware infection. It is recommended to remove the object immediately."
by Avast 6 antivirus.

If you ever had this kind of problem, I found two ways to solve it from the net. But I can only confirm that TDSSKiller works for me, because I not tested the other solution yet (the aswMBR software).

This is how I encounter MBR the first time with Avast 6.
I choose to delete it, and later Avast asks for a boot-time scan. I thought this would sure clean everything, but later after the scan finished, another version of Win32 MBR notification appears...

This time Avast detect MBR using their heuristic method.

Troubled by such annoying detection, I lurk around the web reading others experience removing this rootkit. I tried MBAM, but it didn't detect MBR. I read about Sophos anti-rootkit, Panda anti-rootkit, but I tried TDSSKiller because I've used one of Kaspersky Virus removal tools before. And this is some TDSSKiller screenshots before my MBR problem is finally gone.

Cure this Backdoor Sinowal.knf first.

And then reboot~

Alrighttt~~ No more MBR detected by Avast, alrightttttt~~ (I hope this should not bother me anymore, hurmmm..). Should I made document backup after this? I thought I need to erase my harddisk to eliminate the rootkit trace.. Or maybe not, or may be I need to.


Ooigi.blog: "Rootkit attacks the deep part of our harddisk. Hurmmm.. Tricky? Yes."
:.

No comments:

Post a Comment