Overclock.net - Overclocking.net
     
 
Home Gallery Reviews Blogs Register Today's Posts Mark Forums Read Members List


Go Back   Overclock.net - Overclocking.net > Intel > Intel CPUs

Reply
 
LinkBack Thread Tools
Old 04-09-09   #111 (permalink)
New to Overclock.net
 
Join Date: Apr 2009
Posts: 3

Rep: 0 mastercosby Unknown
Unique Rep: 0
Trader Rating: 0
Default

Ignore the last part of my previous post, I didn't read the whole thread before I posted. Good to know the problem is related though.

What I did find interesting though is that windows live started working again when I booted in debugging mode.
mastercosby is offline   Reply With Quote
Old 04-09-09   #112 (permalink)
New to Overclock.net
 
Join Date: Apr 2009
Posts: 12

Rep: 0 psmith Unknown
Unique Rep: 0
Trader Rating: 0
Default Yeah for RootRepeal!!! and thank you winston

Quote:
Originally Posted by winston View Post
Just finished working on a machine with same symptoms. Try scanning your pc with:

http://rootrepeal.googlepages.com/RootRepeal.zip

Run the program, select File at the bottom, then Scan. Our Dell PC w/ winXP would lock up within an hour or so and emit one continuous beep. Root Repeal found a Master Boot Record virus. Once removed, we ran Malwarebytes and haven't had it lock up yet--12 hours so far!
MBR infected! I can't believe it, the nightmare could be over!

Running in 'debugging mode' I ran RootRepeal, scanning files and NO MBR problem was found. Re-booting without 'debugging mode' and scanning again and immediately the MBR problem shows up - right click, select 'immediate repair and reboot' (or something to that effect) and so far so good.

I also had quite a few 'Stealth Objects' that are no longer there when running RootRepeal again.

Although I've looked I couldn't find any detailed information on 'debugging mode', but it seems it must execute a different kernal (or files that make up the kernal) or even slightly different boot record? (I don't understand the details of the MBR).

So, YOU MUST run RootRepeal without debugging mode on, or it wont find the MBR problem.

If you system won't come up without debugging mode you can try a system restore - to get it to come up. If that doesn't work, from safe mode run MSCONFIG and turn of as many processes as you can (sorta a custom safemode) - although, maybe Rootrepeal works in safemode? Haven't tried it, but chances are it might not find the MBR problem with safemode on...?
psmith is offline   Reply With Quote
Old 04-09-09   #113 (permalink)
New to Overclock.net
 
Join Date: Apr 2009
Posts: 13

Rep: 0 jkaz Unknown
Unique Rep: 0
Trader Rating: 0
Default

RootRepeal also found the MBR rootkit on my computer ;]

Hopefully this is the end...
jkaz is offline   Reply With Quote
Old 04-09-09   #114 (permalink)
New to Overclock.net
 
Join Date: Apr 2009
Posts: 12

Rep: 0 psmith Unknown
Unique Rep: 0
Trader Rating: 0
Default Review Of Anti-Programs used against this virus

Infection caused by: Web page (assume javascript)

Code:
Application                      Found Problem
Anti-Virus
 TrendMicro OfficeScan            No   
 AVG                              No
 ESET                             No
  Others?

Anti-spyware/maleware
 SuperAntiSpyware                 No
 Malwarebytes Anti-Malware        No
 SpybotSearchandDestroy           No
 AVG anti-spyware                 No
 ESET                             No
  Others?

Anti-Rootkit
 Sophos                           No
 GMER                             No
 Rootkit Unhook                   No
 RootRepeal                       YES YES YES
psmith is offline   Reply With Quote
Old 04-09-09   #115 (permalink)
New to Overclock.net
 
Join Date: Apr 2009
Posts: 13

Rep: 0 jkaz Unknown
Unique Rep: 0
Trader Rating: 0
Default

Wait lol after rootrepeal is done scanning how do we remove the files?
jkaz is offline   Reply With Quote
Old 04-09-09   #116 (permalink)
New to Overclock.net
 
Join Date: Apr 2009
Posts: 12

Rep: 0 psmith Unknown
Unique Rep: 0
Trader Rating: 0
Default

Right-click and select immediate repair and reboot. (on the MBR! entry)
psmith is offline   Reply With Quote
Old 04-09-09   #117 (permalink)
New to Overclock.net
 
Join Date: Apr 2009
Posts: 13

Rep: 0 jkaz Unknown
Unique Rep: 0
Trader Rating: 0
Default

Wow i'm an idiot thanks.

Did you also delete other things that came up during the scan? The first scan revealed a ton of things but after I deleted the MBR rootkit most of these disappeared.

There's still a couple things left though and I'm not sure what to do.
jkaz is offline   Reply With Quote
Old 04-09-09   #118 (permalink)
New to Overclock.net
 
Join Date: Apr 2009
Posts: 28

Rep: 0 skoops Unknown
Unique Rep: 0
Trader Rating: 0
Default

You guys, I think we have finally exterminated this virus!

I just ran the RootRepeal program as well, and of course, it found the infected MBR! I immediately stopped the scan, right-clicked on the file and repaired and restarted, just like you guys said to do. As of now, I have not had any freezing, I think we finally figured it out guys!

Thank you so much to the person who found a fix for this horrendous virus, it is greatly appreciated!

So everyone, try running that program, delete the infected MBR and you should be all cleaned up!

Thanks to everyone who participated in this thread as well, we did it guys!
skoops is offline   Reply With Quote
Old 04-09-09   #119 (permalink)
New to Overclock.net
 
Join Date: Apr 2009
Posts: 2

Rep: 0 jaz007 Unknown
Unique Rep: 0
Trader Rating: 0
Default

Awesome guys!
Can't try it as I reformatted my hard drive, but 2 questions:
- what's the name of that virus
- how come it went through my up-to-date antivirus ?
Thanks
jaz007 is offline   Reply With Quote
Old 04-09-09   #120 (permalink)
New to Overclock.net
 
Join Date: Apr 2009
Posts: 28

Rep: 0 skoops Unknown
Unique Rep: 0
Trader Rating: 0
Default

Quote:
Originally Posted by jaz007 View Post
Awesome guys!
Can't try it as I reformatted my hard drive, but 2 questions:
- what's the name of that virus
- how come it went through my up-to-date antivirus ?
Thanks
Didn't really have a name, it just said infected MBR or something along those lines.

That, I have no idea, must be an extremely new virus that hides itself.
skoops is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools



All times are GMT -5. The time now is 08:22 PM.


Overclock.net is a Carbon Neutral Site Creative Commons License

Terms of Service / Forum Rules | Privacy Policy | DMCA Info | Advertising | Become an Official Vendor
Copyright © 2009 Shogun Interactive Development. Most rights reserved.
Page generated in 0.15938 seconds with 8 queries