Go Back   Technibble Forums > General Computers > Tech-to-Tech Computer Help

  Technibble Sponsor

Reply
 
Thread Tools Display Modes
  #11  
Old 08-10-2012, 11:19 AM
RegEdit RegEdit is offline
 
Join Date: Feb 2010
Location: Los Angeles, CA
Posts: 1,634
RegEdit is on a distinguished road
Default

It's still telling me that the MBR code is faked. : (
Quote:
Yes. UBCD4WIN. That's what I have.
I tried this...Start > Programs > Disk Tools > Partition > MBR Fix > Fix / Update a W2K/XP/2005 type MBR code
This is bizarre that I can't even use a Windows CD to enter the recovery console. It's just loading from CD into RAM memory right? How would a virus interfere?

Last edited by RegEdit; 08-10-2012 at 11:27 AM.
Reply With Quote
  #12  
Old 08-10-2012, 11:27 AM
tf76's Avatar
tf76 tf76 is offline
 
Join Date: Apr 2010
Location: South Australia
Posts: 395
tf76 has a spectacular aura abouttf76 has a spectacular aura about
Default

Can you run GMER?


Regards,
Reply With Quote
  #13  
Old 08-10-2012, 11:31 AM
tf76's Avatar
tf76 tf76 is offline
 
Join Date: Apr 2010
Location: South Australia
Posts: 395
tf76 has a spectacular aura abouttf76 has a spectacular aura about
Default

http://www.technibble.com/rootkit-de...removal-tools/

I would remove hd and scan externally with one of these tools.



Regards,
Reply With Quote
  #14  
Old 08-10-2012, 11:44 AM
RegEdit RegEdit is offline
 
Join Date: Feb 2010
Location: Los Angeles, CA
Posts: 1,634
RegEdit is on a distinguished road
Default

Quote:
Originally Posted by tf76 View Post
http://www.technibble.com/rootkit-de...removal-tools/

I would remove hd and scan externally with one of these tools.



Regards,
I was unable to install Avast's anti rootkit.
GMER seems to work.
I need to get an adapter. This ThinkPad has a strange smaller SATA power connector. Not sure what these small SATA power connectors are called.
Reply With Quote
  #15  
Old 08-10-2012, 11:46 AM
tf76's Avatar
tf76 tf76 is offline
 
Join Date: Apr 2010
Location: South Australia
Posts: 395
tf76 has a spectacular aura abouttf76 has a spectacular aura about
Default

Well Kaspersky REscue CD is usually good as well.

Regards,
Reply With Quote
  #16  
Old 08-10-2012, 05:53 PM
RegEdit RegEdit is offline
 
Join Date: Feb 2010
Location: Los Angeles, CA
Posts: 1,634
RegEdit is on a distinguished road
Default

Quote:
Originally Posted by tf76 View Post
Well Kaspersky REscue CD is usually good as well.

Regards,
Kaspersky did something. After running it I was able to install Avast's anti-rootkit tool. Instead of getting a warning about a fake MBR, MBR_Check now says that the MBR is "unknown". That's an improvement for now. I still can't load my Windows CD to run the recovery console though.
Reply With Quote
  #17  
Old 08-10-2012, 06:21 PM
732914TECH 732914TECH is offline
 
Join Date: Dec 2010
Posts: 165
732914TECH is an unknown quantity at this point
Default

Since its XP you can boot to a 98 bootdisk and run "fdisk /mbr" and it will erase the MBR.
Reply With Quote
  #18  
Old 08-10-2012, 06:31 PM
jbartlett323 jbartlett323 is offline
 
Join Date: Apr 2011
Posts: 258
jbartlett323 is on a distinguished road
Default

Quote:
Originally Posted by RegEdit View Post
It's still telling me that the MBR code is faked. : (

This is bizarre that I can't even use a Windows CD to enter the recovery console. It's just loading from CD into RAM memory right? How would a virus interfere?
The Virus isnt interfering, there is something interfering with boot. Most likely it is an AHCI HDD setting, switch to compatibility and it will boot, just switch back before booting OS. This is the common setting for IBM/Lenovo's. You have to have an XP disk with Intel AHCI drivers slipstreamed to boot without changing that setting.
If not, pull the drive and boot the CD. Wont fix your problem, but will help rule out other hardware issues...

Oh, and unless its an SSD, that is an adapter that is removable on the drive, not a special interface....
Reply With Quote
  #19  
Old 08-10-2012, 08:42 PM
RegEdit RegEdit is offline
 
Join Date: Feb 2010
Location: Los Angeles, CA
Posts: 1,634
RegEdit is on a distinguished road
Default

Quote:
Originally Posted by jbartlett323 View Post
The Virus isnt interfering, there is something interfering with boot. Most likely it is an AHCI HDD setting, switch to compatibility and it will boot, just switch back before booting OS. This is the common setting for IBM/Lenovo's. You have to have an XP disk with Intel AHCI drivers slipstreamed to boot without changing that setting.
If not, pull the drive and boot the CD. Wont fix your problem, but will help rule out other hardware issues...

Oh, and unless its an SSD, that is an adapter that is removable on the drive, not a special interface....
Good info to know! I gotta look into how to slip stream AHCI into XP. So I guess my regular XP disks would not install on this machine if I tried? For now I've got these rootkits eradicated. Kaspersky Live CD, Avast anti-rootkit, and ComboFix did the bulk of the work.

It is SSD. I gotta get me an adapter for the next time I encounter one of these...
Reply With Quote
  #20  
Old 08-27-2012, 07:58 AM
BCS Head Tech's Avatar
BCS Head Tech BCS Head Tech is offline
 
Join Date: Nov 2011
Location: California
Posts: 47
BCS Head Tech is an unknown quantity at this point
Send a message via Yahoo to BCS Head Tech
Default

Quote:
Originally Posted by RegEdit View Post
Windows CD keeps blue screening out. MBR is infected. I know because MBR_Check said that the MBR is faked.

Refresh my memory on how to replace the MBR without using the recovery console. ??
try spotman software
__________________
Regards,

Don
BCS Head Tech

BAY COMPUTER SOLUTIONS
www.baycomputerisyoursolution.com
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 04:53 AM.


Powered by vBulletin®
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Technibble.com is based out of MELBOURNE, AUSTRALIA.