Rootkit.MBR.Whistler.A Virus

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Joeb102072, Sep 13, 2011.

  1. Joeb102072

    Joeb102072 Private E-2

    Hi Everyone... I have a quick question before I start the MG malware removal process.

    I know that a rootkit.MBR virus is not uncommon and I know the procedure that is required by the MG team. I have what might be a unique situation and I just want to clarify if I am required to use the malware removal process described by MG.

    BitDefender AV detected and notified me that is has blocked the Rootkit.MBR.Whistler.A Virus from my computer and that access to this file has been denied...it is telling me that.

    Accessed by: Accessing process- (which I assume is common)

    Location: M: <--- That is what is different. My M: Drive is an external HD just a USB plug and play 250GB drive.

    Is the procedure to disinfect my system the same?

    Thank you for your help MG Team!
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go to the below link and follow the instructions for running TDSSKiller from Kaspersky

    Be sure to attach your log from TDSSKiller

    Please also download MBRCheck to your desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  3. Joeb102072

    Joeb102072 Private E-2

    Thank you for your help... here are the logs you requested.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What is this drive:
    37 GB \\.\PhysicalDrive2 Unknown MBR code

    Also, what malware issues are you experiencing?
     
  5. Joeb102072

    Joeb102072 Private E-2

    Its a slaved hard drive... Labeled G: in my list.

    And to my knowledge I am not experiencing any malware issues at least they havent presented themselves to me.

    All I received was the message in my original post from BitDefender.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    All your MBR files are legit, with just that one reporting as unknown. If you aren't having any malware issues, I would just forget about it. ;)
     
  7. Joeb102072

    Joeb102072 Private E-2

    I like to err on the side of caution which is why I contacted you guys on the first sign of something unusual. I VERY much appreciate your help!!! And even though I have only needed to ask for MG help on one other separate occasion, I have since and still do tell everyone I know about you guys. Best informative and resourceful website I have ever seen!!

    Thanks MG!!
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds