Best or your favorite MRB scanner?

yeah mbr...and gmer detects MBR infections too...I forget the exact code it shows, but something like \Device\HardDisk0\DR0 or whatever.

I dealt with Sinowal not too long ago...what a pain.
 
No, that's correct. I believe it says something like 'malicous code found @ sector 02132' or something, but most antivirus software will give you a name

In evaluating this progam I found that I do like it (MBR.exe) but I think it may be giving a fale positive. Every boot sector scanner that I run comes back clen but MBR comes back with malicious code at sector such and such.

I for the life of me can not determine if it has an infection for real or not.
The reason I am skeptical is that there are muliple Dell paritions (Dell Diagnostics, and Dell system restore)

I have this on a system that was actual donated by a client (Never approved repairs and never picked it up) I have the infected images and then what I believe is now a clean image except for the "malicious code"

Any suggestions?
 
Well, one system I had, that had the Mebroot MBR rootkit infection, I used the Avira MBR scanner disc, and it found nothing. The MBR tool however found traces of MBR infection, as well as GMER. Basically, you don't need to know exactly what infection it is...just kill it.
 
Agreed but mbr.exe -f does not fix it and all other program say the MRB is OK.

As a side note I deleted the Dell partisions and then MBR.exe comes back as clean. I really think it is a false positive.
 
Back
Top