How do I remove a copy MBR?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by krebbin, Jul 20, 2009.

  1. krebbin

    krebbin Private E-2

    Hi MG,

    I've run all the cleaning procedures but mbr.exe is reporting an infected copy MBR. Do I need to remove this? If so, can you tell me how?

    I attach the log file for your perusal.

    Many thanks, Krebbin.
     

    Attached Files:

    • mbr.log
      File size:
      324 bytes
      Views:
      10
  2. krebbin

    krebbin Private E-2

    This machine decided to run an NT Authority shutdown (Blaster, Sasser, take yer pick), even though all my tools said it was a clean drive:-(

    Well, I decided to delete the partition, then reformatted the drive using Dos 6 fdisk.
    Then ran an XP install with a re-reformat to NTFS and guess what, it's still bloody there!

    Exactly the same as my attached log.

    I can see I'm going to have to trash this drive, cos this is driving me nuts.
     
  3. krebbin

    krebbin Private E-2

    Ok, I might be talking to myself here, but I've discovered there are only 4 other posts on the net with this problem and none of them got fixed.

    Plus they've all happened in the past 2 weeks.

    I'm going to format a new drive and copy my data to that. It might just leave out the infected bit. I'll let you know.........
     
  4. krebbin

    krebbin Private E-2

    My advice if you get one of these errors after an MBR test:
    copy of MBR has been found in sector 0x0DF8F900
    malicious code @ sector 0x0DF8F903 !
    PE file found in sector at 0x0DF8F919 !


    Backup data, replace drive and copy data to new drive
    On infected drive run HDDGuru's Low level format util
    Clone new to old
    Put old drive back and test with mbr.exe - it will be clean! Hoorah:)
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We have fixed many of these in the last month here. All we needed to do was run fixmbr from the Recovery Console. This fixed the real Mebroot infection that good AVs were detecting, however, sometimes mbr.exe would still report the same malicious code. Some people feel this could be a false detection issue with mbr.exe since they AVs and a few other scans no longer detect a problem after fixmbr was run.
     
  6. krebbin

    krebbin Private E-2

    Hi Chas, Yeah I was working under that assumption too, then I got the NT Authority system shutdown during a printer driver re-install!.

    I'd already ran a few tests for malware and all of them came back clean, so I knew there was something well hidden that was still causing problems.

    ...and I really don't like a system telling me one thing while doing another!!

    S'alright now though:)
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This could have been a different problem. Also may not have even been malware, but after a clean reinstall, all of the problems should be gone so we really would not know what the source of this was now. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds