1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive Posting MBAM MBR check logs instead of Hijack This

Discussion in 'Malware and Virus Removal Archive' started by Judy, 2010/11/05.

Thread Status:
Not open for further replies.
  1. 2010/11/05
    Judy

    Judy Inactive Thread Starter

    Joined:
    2002/11/21
    Messages:
    228
    Likes Received:
    0
    [Inactive] Posting MBAM MBR check logs instead of Hijack This

    HP told me to run Hijack This but am following your instructions instead.

    HP found corruption and suggested Hijack this.

    I could not post DDS since it apparently does not work on 64 bit.

    I am running Vista Home Premium 64 bit

    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Database version: 5046

    Windows 6.0.6002 Service Pack 2
    Internet Explorer 7.0.6002.18005

    11/4/2010 5:08:24 PM
    mbam-log-2010-11-04 (17-08-24).txt

    Scan type: Quick scan
    Objects scanned: 149943
    Time elapsed: 5 minute(s), 15 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
    ===========================
    GMER log shows 0 bytes. -- after running it I could see that there were no infections
    ===========================
    MBRCheck, version 1.2.3
    (c) 2010, AD

    Command-line:
    Windows Version: Windows Vista Home Premium Edition
    Windows Information: Service Pack 2 (build 6002), 64-bit
    Base Board Manufacturer: Quanta
    BIOS Manufacturer: Hewlett-Packard
    System Manufacturer: Hewlett-Packard
    System Product Name: HP Pavilion dv9700 Notebook PC
    Logical Drives Mask: 0x0000001c

    Kernel Drivers (total 169):
    0x02606000 \SystemRoot\system32\ntoskrnl.exe
    0x02B1D000 \SystemRoot\system32\hal.dll
    0x0060F000 \SystemRoot\system32\kdcom.dll
    0x00619000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
    0x00654000 \SystemRoot\system32\PSHED.dll
    0x00668000 \SystemRoot\system32\CLFS.SYS
    0x006C5000 \SystemRoot\system32\CI.dll
    0x0080A000 \SystemRoot\system32\drivers\Wdf01000.sys
    0x008E4000 \SystemRoot\system32\drivers\WDFLDR.SYS
    0x008F2000 \SystemRoot\system32\drivers\acpi.sys
    0x00948000 \SystemRoot\system32\drivers\WMILIB.SYS
    0x00951000 \SystemRoot\system32\drivers\msisadrv.sys
    0x0095B000 \SystemRoot\system32\drivers\pci.sys
    0x0098B000 \SystemRoot\System32\drivers\partmgr.sys
    0x009A0000 \SystemRoot\system32\DRIVERS\compbatt.sys
    0x009A4000 \SystemRoot\system32\DRIVERS\BATTC.SYS
    0x009B0000 \SystemRoot\system32\drivers\volmgr.sys
    0x00777000 \SystemRoot\System32\drivers\volmgrx.sys
    0x009C4000 \SystemRoot\system32\drivers\intelide.sys
    0x009CC000 \SystemRoot\system32\drivers\PCIIDEX.SYS
    0x009DC000 \SystemRoot\System32\drivers\mountmgr.sys
    0x00A08000 \SystemRoot\system32\DRIVERS\iaStor.sys
    0x00B24000 \SystemRoot\system32\drivers\atapi.sys
    0x00B2C000 \SystemRoot\system32\drivers\ataport.SYS
    0x00B50000 \SystemRoot\system32\drivers\msahci.sys
    0x00B5A000 \SystemRoot\system32\drivers\fltmgr.sys
    0x00C0B000 \SystemRoot\system32\drivers\NAVx64\1201000.025\SYMDS64.SYS
    0x00C7C000 \SystemRoot\system32\drivers\fileinfo.sys
    0x00C90000 \SystemRoot\system32\DRIVERS\Lbd.sys
    0x00CA5000 \SystemRoot\system32\drivers\NAVx64\1201000.025\SYMEFA64.SYS
    0x00D73000 \SystemRoot\System32\Drivers\ksecdd.sys
    0x00E0C000 \SystemRoot\system32\drivers\ndis.sys
    0x00BA1000 \SystemRoot\system32\drivers\msrpc.sys
    0x0100A000 \SystemRoot\system32\drivers\NETIO.SYS
    0x01063000 \SystemRoot\System32\drivers\tcpip.sys
    0x00FCF000 \SystemRoot\System32\drivers\fwpkclnt.sys
    0x01203000 \SystemRoot\System32\Drivers\Ntfs.sys
    0x01383000 \SystemRoot\system32\drivers\volsnap.sys
    0x013C7000 \SystemRoot\System32\Drivers\spldr.sys
    0x013CF000 \SystemRoot\System32\Drivers\mup.sys
    0x0140D000 \SystemRoot\System32\drivers\ecache.sys
    0x01439000 \SystemRoot\system32\drivers\disk.sys
    0x0144D000 \SystemRoot\system32\drivers\CLASSPNP.SYS
    0x01479000 \SystemRoot\system32\drivers\crcdisk.sys
    0x015AD000 \SystemRoot\system32\DRIVERS\tunnel.sys
    0x015BA000 \SystemRoot\system32\DRIVERS\tunmp.sys
    0x015C3000 \SystemRoot\system32\DRIVERS\CmBatt.sys
    0x015C8000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
    0x015D1000 \SystemRoot\system32\DRIVERS\intelppm.sys
    0x0240E000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
    0x02F32000 \SystemRoot\system32\DRIVERS\nvBridge.kmd
    0x03000000 \SystemRoot\System32\drivers\dxgkrnl.sys
    0x030E3000 \SystemRoot\System32\drivers\watchdog.sys
    0x030F3000 \SystemRoot\system32\DRIVERS\usbuhci.sys
    0x030FF000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
    0x03145000 \SystemRoot\system32\DRIVERS\usbehci.sys
    0x03205000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
    0x0340D000 \SystemRoot\system32\DRIVERS\NETw5v64.sys
    0x0389F000 \SystemRoot\system32\DRIVERS\Rtlh64.sys
    0x038D9000 \SystemRoot\system32\DRIVERS\ohci1394.sys
    0x038EB000 \SystemRoot\system32\DRIVERS\1394BUS.SYS
    0x038FB000 \SystemRoot\system32\DRIVERS\sdbus.sys
    0x0391B000 \SystemRoot\system32\DRIVERS\rimmpx64.sys
    0x03930000 \SystemRoot\system32\DRIVERS\rimspx64.sys
    0x03947000 \SystemRoot\system32\DRIVERS\rixdpx64.sys
    0x0399E000 \SystemRoot\system32\DRIVERS\HpqRemHid.sys
    0x039A1000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
    0x039B3000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
    0x039BB000 \SystemRoot\system32\DRIVERS\i8042prt.sys
    0x039D1000 \SystemRoot\system32\DRIVERS\HpqKbFiltr.sys
    0x039DD000 \SystemRoot\system32\DRIVERS\kbdclass.sys
    0x032F2000 \SystemRoot\system32\DRIVERS\SynTP.sys
    0x039EB000 \SystemRoot\system32\DRIVERS\USBD.SYS
    0x039ED000 \SystemRoot\system32\DRIVERS\mouclass.sys
    0x03348000 \SystemRoot\system32\DRIVERS\cdrom.sys
    0x03364000 \SystemRoot\system32\DRIVERS\VMNetSrv.sys
    0x039F9000 \SystemRoot\system32\DRIVERS\rcmirror.sys
    0x03379000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
    0x03400000 \SystemRoot\system32\DRIVERS\lmimirr.sys
    0x0339E000 \SystemRoot\system32\DRIVERS\msiscsi.sys
    0x03156000 \SystemRoot\system32\DRIVERS\storport.sys
    0x033D7000 \SystemRoot\system32\DRIVERS\TDI.SYS
    0x031B3000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
    0x033E4000 \SystemRoot\system32\DRIVERS\ndistapi.sys
    0x02F34000 \SystemRoot\system32\DRIVERS\ndiswan.sys
    0x033F0000 \SystemRoot\system32\DRIVERS\raspppoe.sys
    0x031D6000 \SystemRoot\system32\DRIVERS\raspptp.sys
    0x02F65000 \SystemRoot\system32\DRIVERS\rassstp.sys
    0x02F7D000 \SystemRoot\system32\DRIVERS\termdd.sys
    0x03407000 \SystemRoot\system32\DRIVERS\swenum.sys
    0x02F90000 \SystemRoot\system32\DRIVERS\ks.sys
    0x031F4000 \SystemRoot\system32\DRIVERS\mssmbios.sys
    0x02FC4000 \SystemRoot\system32\DRIVERS\umbus.sys
    0x03A0D000 \SystemRoot\system32\DRIVERS\usbhub.sys
    0x03A55000 \SystemRoot\system32\DRIVERS\kbdhid.sys
    0x03A60000 \SystemRoot\System32\Drivers\NDProxy.SYS
    0x03A74000 \SystemRoot\system32\drivers\HdAudio.sys
    0x03ABD000 \SystemRoot\system32\drivers\portcls.sys
    0x03AF8000 \SystemRoot\system32\drivers\drmk.sys
    0x03B1B000 \SystemRoot\system32\drivers\ksthunk.sys
    0x04A09000 \SystemRoot\system32\DRIVERS\smserial.sys
    0x04B3D000 \SystemRoot\system32\drivers\modem.sys
    0x04B4C000 \SystemRoot\system32\drivers\MODEMCSA.sys
    0x04B59000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
    0x04B63000 \SystemRoot\System32\Drivers\Null.SYS
    0x04B6C000 \??\C:\Windows\system32\drivers\SBREdrv.sys
    0x04B7B000 \SystemRoot\System32\drivers\vga.sys
    0x04B89000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
    0x04B92000 \SystemRoot\system32\drivers\rdpencdd.sys
    0x04B9B000 \SystemRoot\System32\Drivers\Msfs.SYS
    0x04BA6000 \SystemRoot\System32\Drivers\Npfs.SYS
    0x04BB7000 \SystemRoot\System32\DRIVERS\rasacd.sys
    0x04BC0000 \SystemRoot\system32\DRIVERS\tdx.sys
    0x03B21000 \SystemRoot\system32\drivers\NAVx64\1201000.025\SYMTDIV.SYS
    0x03B95000 \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS
    0x04C02000 \SystemRoot\System32\DRIVERS\netbt.sys
    0x04C46000 \SystemRoot\system32\DRIVERS\smb.sys
    0x04C61000 \SystemRoot\system32\drivers\afd.sys
    0x04CCC000 \SystemRoot\system32\DRIVERS\pacer.sys
    0x04CEA000 \SystemRoot\system32\DRIVERS\netbios.sys
    0x04CF9000 \SystemRoot\system32\DRIVERS\wanarp.sys
    0x04D14000 \??\C:\Windows\system32\Drivers\vmm.sys
    0x04D61000 \SystemRoot\system32\drivers\NAVx64\1201000.025\Ironx64.SYS
    0x04E07000 \SystemRoot\system32\DRIVERS\snp2uvc.sys
    0x04FBD000 \SystemRoot\system32\DRIVERS\STREAM.SYS
    0x04FCE000 \SystemRoot\system32\DRIVERS\sncduvc.SYS
    0x04D8D000 \SystemRoot\system32\DRIVERS\ATSwpDrv.sys
    0x04FD7000 \SystemRoot\system32\drivers\NAVx64\1201000.025\SRTSPX64.SYS
    0x05007000 \SystemRoot\system32\DRIVERS\rdbss.sys
    0x05054000 \SystemRoot\system32\drivers\nsiproxy.sys
    0x05060000 \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\IPSDefs\20101103.001\IDSvia64.sys
    0x050DB000 \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys
    0x05151000 \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
    0x05176000 \SystemRoot\System32\Drivers\dfsc.sys
    0x05201000 \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\BASHDefs\20101029.001\BHDrvx64.sys
    0x052EE000 \SystemRoot\System32\Drivers\crashdmp.sys
    0x01483000 \SystemRoot\System32\Drivers\dump_iaStor.sys
    0x00020000 \SystemRoot\System32\win32k.sys
    0x052FC000 \SystemRoot\System32\drivers\Dxapi.sys
    0x05308000 \SystemRoot\system32\DRIVERS\monitor.sys
    0x00490000 \SystemRoot\System32\TSDDD.dll
    0x00610000 \SystemRoot\System32\cdd.dll
    0x00800000 \SystemRoot\System32\rcmirror.dll
    0x0531B000 \SystemRoot\system32\drivers\luafv.sys
    0x0533D000 \SystemRoot\system32\drivers\spsys.sys
    0x053D7000 \SystemRoot\system32\DRIVERS\lltdio.sys
    0x05193000 \SystemRoot\system32\DRIVERS\nwifi.sys
    0x053EB000 \SystemRoot\system32\DRIVERS\ndisuio.sys
    0x051C7000 \SystemRoot\system32\DRIVERS\rspndr.sys
    0x04DC1000 \SystemRoot\System32\DRIVERS\srvnet.sys
    0x051DF000 \SystemRoot\system32\DRIVERS\bowser.sys
    0x04BDD000 \SystemRoot\System32\drivers\mpsdrv.sys
    0x03BCB000 \SystemRoot\system32\drivers\mrxdav.sys
    0x02FD4000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
    0x08A05000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
    0x08A4E000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
    0x08A6D000 \SystemRoot\System32\DRIVERS\srv2.sys
    0x08A9F000 \SystemRoot\System32\DRIVERS\srv.sys
    0x08B33000 \SystemRoot\system32\drivers\HTTP.sys
    0x08BD6000 \??\C:\Windows\system32\drivers\LMIRfsDriver.sys
    0x09403000 \SystemRoot\system32\drivers\peauth.sys
    0x094B9000 \SystemRoot\System32\Drivers\secdrv.SYS
    0x094C4000 \SystemRoot\System32\drivers\tcpipreg.sys
    0x094D4000 \??\C:\Program Files (x86)\HP\QuickPlay\000.fcl
    0x094FB000 \SystemRoot\system32\drivers\NAVx64\1201000.025\SRTSP64.SYS
    0x0AC06000 \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20101104.057\EX64.SYS
    0x0ADC4000 \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20101104.057\ENG64.SYS
    0x0ADE4000 \SystemRoot\system32\DRIVERS\cdfs.sys
    0x77950000 \Windows\System32\ntdll.dll

    Processes (total 69):
    0 System Idle Process
    4 System
    516 C:\Windows\System32\smss.exe
    620 csrss.exe
    664 C:\Windows\System32\wininit.exe
    684 csrss.exe
    724 C:\Windows\System32\services.exe
    736 C:\Windows\System32\lsass.exe
    744 C:\Windows\System32\lsm.exe
    892 C:\Windows\System32\svchost.exe
    952 C:\Windows\System32\nvvsvc.exe
    980 C:\Windows\System32\svchost.exe
    404 C:\Windows\System32\svchost.exe
    436 C:\Windows\System32\svchost.exe
    448 C:\Windows\System32\svchost.exe
    596 C:\Windows\System32\winlogon.exe
    820 C:\Windows\System32\audiodg.exe
    432 C:\Windows\System32\svchost.exe
    528 C:\Windows\System32\SLsvc.exe
    1060 C:\Windows\System32\svchost.exe
    1152 C:\Windows\System32\svchost.exe
    1284 C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
    1348 C:\Windows\System32\spoolsv.exe
    1372 C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe
    1452 C:\Windows\System32\svchost.exe
    1816 C:\Windows\System32\svchost.exe
    1848 C:\Program Files (x86)\1st Clock\1stClockAdjustTimeSvc.exe
    1880 C:\Windows\SysWOW64\svchost.exe
    1984 C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
    2044 C:\Program Files (x86)\Common Files\Motive\McciCMService.exe
    1140 C:\Program Files\Common Files\Motive\McciCMService.exe
    876 C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
    628 C:\Windows\System32\msiexec.exe
    1772 C:\Program Files (x86)\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe
    1832 C:\Windows\System32\svchost.exe
    2052 C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
    2148 C:\Windows\System32\svchost.exe
    2184 C:\Windows\System32\svchost.exe
    2220 C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
    2296 C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
    2440 dllhost.exe
    2684 C:\Windows\System32\nvvsvc.exe
    2828 C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
    2860 C:\Windows\System32\svchost.exe
    2904 C:\Windows\System32\svchost.exe
    2948 C:\Windows\System32\svchost.exe
    2972 C:\Windows\System32\SearchIndexer.exe
    2132 C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
    720 C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
    3292 WmiPrvSE.exe
    3300 iashost.exe
    3352 C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe
    3684 C:\Windows\System32\taskeng.exe
    3512 C:\Program Files (x86)\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe
    1260 C:\Program Files (x86)\DigitalPersona\Bin\DpAgent.exe
    3504 C:\Windows\System32\taskeng.exe
    2632 C:\Windows\explorer.exe
    4072 C:\Program Files (x86)\DigitalPersona\Bin\x64\DpAgent.exe
    2928 C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    3800 C:\Program Files (x86)\Macro Express3\MacExp.exe
    3144 C:\Program Files (x86)\1st Clock\1stClock.exe
    976 C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe
    3996 C:\Windows\System32\SearchProtocolHost.exe
    3644 C:\Windows\System32\SearchFilterHost.exe
    3884 C:\Program Files (x86)\1st Clock\ClockApi64.exe
    1712 C:\Windows\System32\svchost.exe
    3936 unsecapp.exe
    3728 WmiPrvSE.exe
    4784 C:\Users\Judy\Desktop\MBRCheck.exe

    \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
    \\.\D: --> \\.\PhysicalDrive0 at offset 0x00000047`3198ee00 (NTFS)

    PhysicalDrive0 Model Number: WDCWD3200BEVT-60ZCT0, Rev: 11.01A11

    Size Device Name MBR Status
    --------------------------------------------
    298 GB \\.\PhysicalDrive0 Unknown MBR code
    SHA1: D94F393960D1CD66C2071F2D7260A5196DF105AC


    Found non-standard or infected MBR.
    Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    Options:
    [1] Dump the MBR of a physical disk to file.
    [2] Restore the MBR of a physical disk with a standard boot code.
    [3] Exit.

    Enter your choice: Enter the physical disk number to fix (0-99, -1 to cancel): 3Available MBR codes:
    [ 0] Default (Windows Vista)
    [ 1] Windows XP
    [ 2] Windows Server 2003
    [ 3] Windows Vista
    [ 4] Windows 2008
    [ 5] Windows 7
    [-1] Cancel

    Please select the MBR code to write to this drive: 3
    Do you want to fix the MBR code? Type 'YES' and hit ENTER to continue: yes
    Error opening disk (2)!


    Done!
    =========================

    I was not able to perfrom all that was suggested.
    Thanks for your evaluation.
     
    Judy,
    #1
  2. 2010/11/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    HJT is a very outdated tool, so we don't use it anymore.

    DDS will run on 64-bit.
    Please, retry, or let me know, what problem you're having while trying to run DDS.
     

  3. to hide this advert.

  4. 2010/11/07
    Judy

    Judy Inactive Thread Starter

    Joined:
    2002/11/21
    Messages:
    228
    Likes Received:
    0
    I did not disable script blocking. Don't have a clue how to do so.
    I thought it might be inside the DDS program, but in googling I found that it is apparently not.

    When I click on RUN, the black screen opens but closes faster than I can read it.

    Will you point me in the right direction on how to disable script blocking.

    Thanks very much.
     
    Judy,
    #3
  5. 2010/11/07
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    That's probably not your fault, but something on your computer is preventing DDS from running.
    Do you use Spybot, or Windows Defender?

    Let's start with fixing your MBR.

    Please download NTBR by noahdfear and save it to your Desktop.
    File size: 2.44 MB (2,565,432 bytes)

    • Place a blank CD in your CD drive.
    • Double click on NTBR_CD.exe file and a folder of the same name will appear.
    • Open the folder and double click on BurnItCD.cmd file. If your CD drive will open, simply close it back.
    • Follow the prompts to burn the CD.
    • Now you will need to set the CD-Rom as first boot device if it isn't already (if you don't know how to do it, see HERE)
    • If you have any questions about this step, ask before you proceed. If you enter the BIOS and are unsure if you have carried out the step correctly, there should be an option to exit without keeping changes, so you won't do any harm.
    • Insert the newly created CD into your infected PC and reboot your computer.
    • Once you have rebooted please press Enter when prompted to continue booting from CD - you have a whole 15 seconds to do this!
    • Read the warning and then continue as prompted.
    • You first need to select your keyboard layout - press Enter for English.
    • Next you want to select the appropriate tool. Enter 1 to choose 1. MBRWORK
    • On the following screen enter 5 to select Install Standard MBR code.
    • Enter 1 to overwrite the infected MBR Code with the Standard MBR code.
    • When asked to confirm please do so.
    • Afterwards, please enter E to leave MBRWORK, then 6 to leave the bootable CD.
    • Eject the disc and then press ctrl+alt+del to reboot the PC.
    Once rebooted, run MBRCheck again and post its log.
     
  6. 2010/11/08
    Judy

    Judy Inactive Thread Starter

    Joined:
    2002/11/21
    Messages:
    228
    Likes Received:
    0
    I use Spybot, but use it manually. It does not run in the background. I do not use Windows Defender

    Would Ad-Aware cause a problem? That does run in the background.

    I cannot disable script blocking, but I can un-install my AV if you think that would help

    I feel uncomfortable with the NTBR option.

    What else can I do to get this DDS to run?

    The other programs did not show any infections. Do I need to run the DDS?

    Thanks
     
    Judy,
    #5
  7. 2010/11/08
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Unfortunately, it has to be done.
     
  8. 2010/11/10
    Judy

    Judy Inactive Thread Starter

    Joined:
    2002/11/21
    Messages:
    228
    Likes Received:
    0
    I was contacted last night by my AV tech support and now they say that script blocking can be done.

    So, I will try that.

    Should I disable Ad-Aware?
     
    Judy,
    #7
  9. 2010/11/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You need to reset MBR using NTBR CD.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.