Whistler/Black internet

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mensaap, Jan 31, 2011.

  1. mensaap

    mensaap Private E-2

    Hello,

    I ran avast today and it detected the Whistler@mbr virus.
    Now, I've been searching on google and your forums and so far I've done the following:

    -I've run mbrcheck.exe multiple times, didn't work
    -I tried using the windows 7 bootdisk

    The weird thing is that it's not my main drive that's infected (my w7 drive) but another drive which is used for my steam games.

    I haven't had any problems with popup ads or iexplorer.exe running in the background.

    Should I be worried, and how can I fix this problem?

    MBRCheck log:
     

    Attached Files:

    Last edited by a moderator: Jan 31, 2011
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    • Download bootkit_remover.rar
    • Click the underlined DOWNLOAD text to download the file and save it to your Desktop.
    • You then need to extract the remover.exe file from the RAR using a program capable of extracing RAR compressed files. If you don't have an extraction program, you can use7-Zip
    • After extracing remover.exe to your Desktop, double click the remover.exe file to run the program.
    • Attach or post inline here, the output from remover.exe
     
  3. mensaap

    mensaap Private E-2

    Attached the file

    PS. Should I be worried about personal data, recently used paypal, etc...
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That is not the correct output. I should be seeing something like this for example:

    If you do online banking and you are infected with this then you will need to change your online passwords from another clean computer.
     
  5. mensaap

    mensaap Private E-2

    Yeah, how do I get the correct output?

    As I've said in my OP, the virus isn't on my w7 drive but on a different drive
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So just run the program again and take a screenshot of the results, which should be something like my example previously given. I realise it's not being detected on your main drive, I just wanted more information. :)
     
  7. mensaap

    mensaap Private E-2

    sorry, I forgot to unpack the readme, got it
     

    Attached Files:

    • log.png
      log.png
      File size:
      41.2 KB
      Views:
      5
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you run MGTools as per the instructions and attach the log it produces @ C:\MGLogs.zip, please?

    Using MGtools
     
  9. mensaap

    mensaap Private E-2

    Here you go
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What drive is this:
    931 GB \\.\PhysicalDrive0

    Re-run MBRCheck and attach the new log.
     
  11. mensaap

    mensaap Private E-2

    It's the drive I use for all my steamgames, I never copy anything on there myself, nor do I ever install something other then steam on that drive

    Here's the log
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    So this is only a storage drive? It is partitioned into E: and F:. Do you have your Win7 disc? If so, reboot into the bios and change your boot order to have the CD Drive as your first boot device. Put in your Win7 disc and reboot.
    Remove the disc and reboot into normal mode and re-run MBRCheck and attach that log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds