Author Topic: MBR:whistler-C [rtk]  (Read 11725 times)

0 Members and 1 Guest are viewing this topic.

fraise

  • Guest
MBR:whistler-C [rtk]
« on: October 27, 2011, 11:54:32 PM »
Hello there I have been having this alert for the past 2 weeks, I reformatted my C drive and it is still there. It seems that it is on my other drive E, I think, but it doesn't say anywhere where its located exactly though.

Disk 0 Masterboot Record MBR:whistler-C [rtk]

What should do?

thank you.





Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37554
  • Not a avast user
Re: MBR:whistler-C [rtk]
« Reply #1 on: October 28, 2011, 12:02:25 AM »
* download aswMBR and save to desktop  http://public.avast.com/~gmerek/aswMBR.exe
* click the aswMBR icon to run
* click scan...On completion of the scan click "save log" post here in next reply

fraise

  • Guest
Re: MBR:whistler-C [rtk]
« Reply #2 on: October 28, 2011, 12:09:31 AM »
ok attached

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37554
  • Not a avast user
Re: MBR:whistler-C [rtk]
« Reply #3 on: October 28, 2011, 12:17:54 AM »
does not show as whistler there.....maybe a new version ?


follow the guide here and attach the logs, then essexboy will have a look tomorrow
http://forum.avast.com/index.php?topic=53253.0


he is usually in here around 08:00pm - 11:59pm UK time....

fraise

  • Guest
Re: MBR:whistler-C [rtk]
« Reply #4 on: October 28, 2011, 12:55:15 AM »
Hi ok here is a screen shot , I will attach those other logs after I finish with the malwarebytes log


fraise

  • Guest
Re: MBR:whistler-C [rtk]
« Reply #5 on: October 28, 2011, 02:45:22 AM »
Ok here are the other logs

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: MBR:whistler-C [rtk]
« Reply #6 on: October 28, 2011, 07:43:40 PM »
Quote
08:43:08.063    Disk 0  \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP4T0L0-4
08:43:08.065    Disk 0 Vendor: WDC_WD1001FALS-00K1B0 05.00K05 Size: 953869MB BusType: 3
08:43:08.072    Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP5T0L0-5
08:43:08.075    Disk 1 Vendor: Patriot_Pyro 319ABBF0 Size: 57241MB BusType: 3
08:43:10.082    Disk 1 MBR read successfully
08:43:10.086    Disk 1 MBR scan
08:43:10.090    Disk 1 Windows 7 default MBR code
This is where the problem resides .. Disc 0 is not configured as a boot drive but it has an MBR and that is what is being detected.
It in itself is not a problem but to clear the alert you will need to reformat that disc (I believe that will be the E drive )  Or I can place an inert MBR on there for you

fraise

  • Guest
Re: MBR:whistler-C [rtk]
« Reply #7 on: October 28, 2011, 08:48:58 PM »
Quote
08:43:08.063    Disk 0  \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP4T0L0-4
08:43:08.065    Disk 0 Vendor: WDC_WD1001FALS-00K1B0 05.00K05 Size: 953869MB BusType: 3
08:43:08.072    Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP5T0L0-5
08:43:08.075    Disk 1 Vendor: Patriot_Pyro 319ABBF0 Size: 57241MB BusType: 3
08:43:10.082    Disk 1 MBR read successfully
08:43:10.086    Disk 1 MBR scan
08:43:10.090    Disk 1 Windows 7 default MBR code
This is where the problem resides .. Disc 0 is not configured as a boot drive but it has an MBR and that is what is being detected.
It in itself is not a problem but to clear the alert you will need to reformat that disc (I believe that will be the E drive )  Or I can place an inert MBR on there for you

Hi sorry I don't quite understand , is the  MBR:whistler-C [rtk] a problem? This drive is my storage drive so if I reformat it , it would clear all my data.

What should I do?

Thank you for your help I really appreciate it.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: MBR:whistler-C [rtk]
« Reply #8 on: October 28, 2011, 08:52:02 PM »
If you wish I can replace that MBR with a replacement

Please download MBRCheck.exe to your Desktop. Run the application.
 
If no infection is found, it will produce a report on the desktop. Post that report in your next reply.
 
If an infection is found, you will be presented with the following dialog:
 
Quote
Enter 'Y' and hit ENTER for more options, or 'N' to exit: 

 
Type N and press Enter. A report will be produced on the desktop. Post that report in your next reply.

fraise

  • Guest
Re: MBR:whistler-C [rtk]
« Reply #9 on: October 28, 2011, 09:02:48 PM »
Hi ok here it is attached , I don't know much about these viruses so I will go with what you say maybe a replacement is best?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: MBR:whistler-C [rtk]
« Reply #10 on: October 28, 2011, 09:27:42 PM »
Lets put a windows 7 MBR there

Run MBRCheck.exe once again.
 
You will be presented with the following dialog:
 
Quote
Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:

 
Enter Y and press Enter.
 
The following dialog will be presented:
Quote
Options:
[1] Dump the MBR of a physical disk to file.
[2] Restore the MBR of a physical disk with a standard boot code.
[3] Exit.
 
Enter your choice:

 
Enter 2 and press Enter
 
The following dialog will be presented:
 
Quote
Enter the physical disk number to fix (0-99, -1 to cancel):

 
Enter >>0<< and press Enter
 
The following dialog will be presented:
Quote

Available MBR codes:
[ 0] Default (Windows XP)
[ 1] Windows XP
[ 2] Windows Server 2003
[ 3] Windows Vista
[ 4] Windows 2008
[ 5] Windows 7
[-1] Cancel
 
Please select the MBR code to write to this drive:

 
Enter >>5<<  and press Enter
 
The following dialog will be presented:
Quote
Do you want to fix the MBR code? Type 'YES' and hit ENTER to continue:

 
Type YES and press Enter (Must type the full word, YES). You will be inform if successfully wrote a new MBR code!
 
And last the following dialog will be presented:
 
Quote
Done! Press ENTER to exit...

 
Press Enter. A report will be produced on the desktop. Post that report in your next reply.

fraise

  • Guest
Re: MBR:whistler-C [rtk]
« Reply #11 on: October 28, 2011, 09:47:55 PM »
ok did it attached

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: MBR:whistler-C [rtk]
« Reply #12 on: October 28, 2011, 09:58:30 PM »
Could you confirm the alerts have now ceased

fraise

  • Guest
Re: MBR:whistler-C [rtk]
« Reply #13 on: October 28, 2011, 10:00:44 PM »
ok let me do a scan

fraise

  • Guest
Re: MBR:whistler-C [rtk]
« Reply #14 on: October 28, 2011, 10:06:22 PM »
it still says its there, here is screen shot