MBR Code Faked

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by sorbitol_co, Dec 27, 2011.

  1. sorbitol_co

    sorbitol_co Private E-2

    So, I am getting redirected to "get answers fast"
    I have run the MBRCheck and it reports:
    "MBR Code Faked" (log attached)
    I have also run the MGTools and the zip file of logs is attached.
    How can I fix this and prevent from happening.
    I bought kaspersky and mallwarebytes but they cant find a problem.
    I don't have either installed at this present time.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Let's see if we can get your PC to boot up into the System Recovery Options. Normally this comes preinstalled as part of Vista and Win 7 PCs. Sometimes, it is possible to repair an MBR from this.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    Startup Repair
    System Restore
    Windows Complete PC Restore
    Windows Memory Diagnostic Tool
    Command Prompt

    • Select Command Prompt
    • At the command prompt, type in the below commands and hit enter. The last command will cause your PC to reboot. Allow it to boot normally.
    bootrec /fixmbr
    exit
    After reboot, rerun MBRcheck as you did earlier and then attach a new log from it.
     
  3. sorbitol_co

    sorbitol_co Private E-2

    I ran the bootrec fixmbr option from a windows 7 repair disk and then reran the fixmbr and it still reports I have issues. The google redirect still seems to happen :(. Any ideas ?
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why didn't you attach the log from ComboFix? Did you have a problem running it? Also what about the logs from SUPERAntiSpyware and Malwarebytes?

    It looks like you may have some new kond of MBR infection unless I'm reading something wrong in your logs. Can you explain why I see two 581.11 GB size drive letters ( C and S ) but you only have one physical drive of that size in your system. I see the below?

    Code:
    Get Logical Disk Info From WMI                                  
    ==============================================================  
    Description       DeviceID  FileSystem  Size          VolumeName  
    Local Fixed Disk  C:        NTFS        623961436160  OS          
    CD-ROM Disc       E:                                              
    Removable Disk    F:                                              
    Removable Disk    G:                                              
    Removable Disk    H:                                              
    Removable Disk    I:                                              
    CD-ROM Disc       M:                                              
    Local Fixed Disk  S:        NTFS        623961436160  OS          
     
    Get Disk Drive Info From WMI                                    
    ==============================================================  
    Model                             Name                Size          
    WDC WD6400AAKS-75A7B0 ATA Device  [URL="file://\\.\PHYSICALDRIVE0"]\\.\PHYSICALDRIVE0[/URL]  640132416000  
    TEAC USB   HS-CF Card USB Device  [URL="file://\\.\PHYSICALDRIVE1"]\\.\PHYSICALDRIVE1[/URL]                
    TEAC USB   HS-MS Card USB Device  [URL="file://\\.\PHYSICALDRIVE3"]\\.\PHYSICALDRIVE3[/URL]                
    TEAC USB   HS-SD Card USB Device  [URL="file://\\.\PHYSICALDRIVE4"]\\.\PHYSICALDRIVE4[/URL]                
    TEAC USB   HS-xD/SM USB Device    [URL="file://\\.\PHYSICALDRIVE2"]\\.\PHYSICALDRIVE2[/URL]                
     
    Get Partition Info From WMI in K-bytes                          
    ==============================================================  
    Bootable  Name                   Size          Type                     
    FALSE     Disk #0, Partition #0  65769984      Unknown                  
    TRUE      Disk #0, Partition #1  623961440256  Installable File System  
    
    Does this possiblye have anything to do with using VirtualClone?
     
  5. sorbitol_co

    sorbitol_co Private E-2

    I have one drive that is SUBST for a path in another.
    So the drive S is mapped to a "SERVER" directory on the c drive.
    I just attached the combofix logs.
    I have run a full scan from malware bytes but did not see a log file.
    I can run it again if that helps.

    I am also attaching the RSIT logs if that helps.

    Thanks for all your help!

    Nelson
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    • Be sure to attach your log from TDSSKiller

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • the TDSSkiller log
    • C:\MGlogs.zip
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds