![]() |
| |||||||
|
![]() |
| | Thread Tools |
|
#11
| |||
| |||
| ok 007, here are the next 2 logs you requested. the mbr log when ran from c:/windows... Stealth MBR rootkit detector 0.2.4 by Gmer, http://www.gmer.net device: opened successfully user: MBR read successfully kernel: MBR read successfully user & kernel MBR OK malicious code @ sector 0x4c8ed45 size 0x1ae ! copy of MBR has been found in sector 62 ! it looks the same to me... and the gmer.log directly after the reboot.... GMER 1.0.15.14939 - http://www.gmer.net Rootkit scan 2009-03-15 18:49:39 Windows 5.1.2600 Service Pack 3 ---- Disk sectors - GMER 1.0.15 ---- Disk \Device\Harddisk0\DR0 sector 61: malicious code @ sector 0x4c8ed45 size 0x1ae Disk \Device\Harddisk0\DR0 sector 62: copy of MBR ---- EOF - GMER 1.0.15 ---- as for why I didnt think the online scanner finished everything, well I lookd at it right before going outside and it was only at 7%. it had been scanning for almost an hour at that point. I was outside long enough to feed my puppy and change his water, lets say 10 minutes, and when I had returned the scan was completed. just felt that if it took an hour to get to only 7%, then how could it complete the scan in such a short time from that point. just didnt make sense to me. not sure if I had mentioned before, but one of the anti virus scanners I was using had to be removed and uninstalled in the beginning. Fix-it utilities 8. for some reason I could not disable the program, even from the start up menu or from the program itself. it just didnt give me the option. without that program installed, things seem to be running a little faster, but malwarebytes still shows the vundo h. this scanner (fix-it) however could see it and it always reported it as removed successfully, but it still showed with malwarebytes, though it could never remove it either... thanks again... |
|
#12
| ||||||||||||
| ||||||||||||
| Hi there theprodigycmb Just to let you know I have not forgetten you.... I am in the process of checking your MBR Boot Record with other experts and will get back to you as soon as permissable.
__________________
__________________
Proud member of ASAP & UNITE My System: Steves Rig
|
|
#13
| |||
| |||
| do what you've gotta do my friend. appreciate the info. |
|
#14
| |||
| |||
| Hi there Your MBR Boot record is clear. I notice that you have Malwarebytes Antimalware (MBAM) installed I want you to run a scan for me.. First I want you to update MBAM so we have the latest definitions onboard Please open Malwarebytes Antimalware Now click on the update tab Next - Click on the Check for updates button.
=============================== Please run a fresh scan with combofix. If you get a requester asking to update combofix please allow it to do so. Post back with both logs in your next reply, also update me on how things are running
__________________ Proud member of ASAP & UNITE |
![]() |
|
| Bookmarks |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Trojan Vundo.H Will Not Go Away. | jbrac25 | Virus, Spyware & Security | 6 | 15th May 2009 13:12 |
| Need Help... Can't Get Rid of TROJAN.VUNDO.H. | sukun | Virus, Spyware & Security | 1 | 2nd May 2009 16:27 |
| Need Help w/ Trojan.Vundo H! | Nicholas02 | Virus, Spyware & Security | 22 | 22nd Dec 2008 17:59 |
| Trojan.vundo.h , trojan.agent , adware.mirar + MORE! :( | sillyarfer | Virus, Spyware & Security | 1 | 14th Dec 2008 09:59 |
| Whatever I do I can't get rid of TROJAN.VUNDO.H | redsowwer | Virus, Spyware & Security | 25 | 3rd Nov 2008 18:10 |
| Thread Tools | |
| |