Came to work today to find there is a some kind of rootkit infection on one of a computers, this poses a huge problem for us since it controls a machine nessicary for the running of the business. Symptoms include, very slow running performance, 90% of programs refuseing to open or giving "XXXX experienced a problem and had to close" occasional loss of interface (toolbar etc disappearing temporarily.
I ran a Avast Virus scan and detected MBR:\\.\physicalDrive0\partition2, Rootkit: hidden Boot_Sector. I attempted to delete this and it gave the message deletion delayed till reboot. I then i attempted rebooting, no change. I then ran a boot scan and it detected 3 corrupt files and what I believe was the rookit which appeared to originate from a file named "Fedex Invoice" which i suspect one of my colleges opened in an email. I then had the option to "Delete all, delete, chest, chest all etc" I attempted to delete them twice but received the message "0XC0000035 {Object name already exists}" then n the third attempt it confirmed that they files had been deleted.
It then continued the scan as usual and proceeded to start up. However no change at all, still not able to open programs and still extremely slow. I did another scan and this time Avast detected "MBR: Aluron-K P [RTK]" obviously, not good. I downloaded aswMBR in an attempt to get more info and delete the bloody thing. However once download it will not run, no error message or crash file, simply does not run. I then downloaded tdsskiller in hope this may run, downloaded, unzipped but same thing, will not run.
Specs are as follows:
Machine name: ENGRAVING-FRONT
Operating System: Windows XP Professional (5.1, Build 2600) Service Pack 3 (2600.xpsp_sp3_gdr.111025-1629)
Language: English (Regional Setting: English)
System Manufacturer: INTEL_
System Model: D945GNT_
BIOS: Default System BIOS
Processor: Intel® Pentium® 4 CPU 3.40GHz (2 CPUs)
Memory: 1022MB RAM
Page File: 542MB used, 1917MB available
Windows Dir: C:\WINDOWS
DirectX Version: DirectX 9.0c (4.09.0000.0904)
DX Setup Parameters: Not found
DxDiag Version: 5.03.2600.5512 32bit Unicode
Display Devices
---------------
Card name: NVIDIA GeForce 6600
Manufacturer: NVIDIA
Chip type: GeForce 6600
DAC type: Integrated RAMDAC
Device Key: Enum\PCI\VEN_10DE&DEV_0141&SUBSYS_00000000&REV_A2
Display Memory: 256.0 MB
Current Mode: 1440 x 900 (32 bit) (60Hz)
Monitor: Plug and Play Monitor
Monitor Max Res: 1600,1200
Driver Name: nv4_disp.dll
Driver Version: 6.14.0011.8618 (English)
DDI Version: 9 (or higher)
Driver Attributes: Final Retail
Driver Date/Size: 6/10/2009 07:03:00, 5908608 bytes
WHQL Logo'd: n/a
WHQL Date Stamp: n/a
VDD: n/a
Mini VDD: nv4_mini.sys
Mini VDD Date: 6/10/2009 07:03:00, 8087712 bytes
Device Identifier: {D7B71E3E-4201-11CF-1A42-0B2003C2CB35}
Vendor ID: 0x10DE
Device ID: 0x0141
SubSys ID: 0x00000000
Revision ID: 0x00A2
Revision ID: 0x00A2
Video Accel: ModeMPEG2_C ModeMPEG2_D ModeWMV9_B ModeWMV9_A
Deinterlace Caps: {6CB69578-7617-4637-91E5-1C02DB810285}: Format(In/Out)=(YUY2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY DeinterlaceTech_PixelAdaptive
{335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(YUY2,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY DeinterlaceTech_BOBVerticalStretch
{6CB69578-7617-4637-91E5-1C02DB810285}: Format(In/Out)=(UYVY,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY DeinterlaceTech_PixelAdaptive
{335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(UYVY,YUY2) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY DeinterlaceTech_BOBVerticalStretch
{6CB69578-7617-4637-91E5-1C02DB810285}: Format(In/Out)=(YV12,0x3231564e) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY DeinterlaceTech_PixelAdaptive
{335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(YV12,0x3231564e) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY DeinterlaceTech_BOBVerticalStretch
{6CB69578-7617-4637-91E5-1C02DB810285}: Format(In/Out)=(NV12,0x3231564e) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY DeinterlaceTech_PixelAdaptive
{335AA36E-7884-43A4-9C91-7F87FAF3E37E}: Format(In/Out)=(NV12,0x3231564e) Frames(Prev/Fwd/Back)=(0,0,0) Caps=VideoProcess_YUV2RGB VideoProcess_StretchX VideoProcess_StretchY DeinterlaceTech_BOBVerticalStretch
Registry: OK
DDraw Status: Enabled
D3D Status: Enabled
AGP Status: Enabled
DDraw Test Result: Not run
D3D7 Test Result: Not run
D3D8 Test Result: Not run
D3D9 Test Result: Not run
Really, i'm at a complete loss of what to try next, I'm now getting semi regular alerts of avast blocking internet explorer opening a page (Assumeing it's some kind of popup) also a message saying avast has detected a rootkit "MBR: Alurec" allows me to delete it, then suggests i restart and do a bootscan however once again this does nothing.
Please help, need it ASAP!
Thank you in advance.