Author Topic: Windows XP MBR code detected  (Read 4241 times)

So yeah, I'm not sure how or when I got it but I ran  virus scan the other day because my computer has been running slower than usual. Avast can't get rid of it and I've run a spybot scan(a friend's advice) which didn't find it. I also tried running MBRCheck and chose to repair the mbr but that didn't work.
Anyone have any advice as to how to be rid of this pesky thing?

The other problem is resolved but now MBRCheck says, "Windows XP MBR code detected" and I'm using Windows 7 64 bit. Is this going to be a problem or will it be fine?
« Last Edit: January 17, 2011, 12:20:12 PM by Littledude »


Also do you really have any other proof you're infected besides your computer is slower?

Also do you really have any other proof you're infected besides your computer is slower?
avast virus scan says I have it as does the MBRCheck

It's just that they fail to fix it.

avast virus scan says I have it as does the MBRCheck

It's just that they fail to fix it.
What message does it give you after it fails to check.

Like

"Holy stuff it didn't work, run for the hills!"?

Code: [Select]
MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows 7 Home Premium Edition
Windows Information: (build 7600), 64-bit
Base Board Manufacturer: ASUSTeK Computer INC.
BIOS Manufacturer: American Megatrends Inc.
System Manufacturer: System manufacturer
System Product Name: System Product Name
Logical Drives Mask: 0x000001fc

Kernel Drivers (total 199):
  0x02E07000 \SystemRoot\system32\ntoskrnl.exe
  0x033E3000 \SystemRoot\system32\hal.dll
  0x00BBF000 \SystemRoot\system32\kdcom.dll
  0x00C5E000 \SystemRoot\system32\mcupdate_AuthenticAMD.dll
  0x00C6B000 \SystemRoot\system32\PSHED.dll
  0x00C7F000 \SystemRoot\system32\CLFS.SYS
  0x00CDD000 \SystemRoot\system32\CI.dll
  0x00E8A000 \SystemRoot\system32\drivers\Wdf01000.sys
  0x00F2E000 \SystemRoot\system32\drivers\WDFLDR.SYS
  0x01048000 \SystemRoot\System32\Drivers\spdr.sys
  0x0116E000 \SystemRoot\System32\Drivers\WMILIB.SYS
  0x01177000 \SystemRoot\System32\Drivers\SCSIPORT.SYS
  0x011A6000 \SystemRoot\system32\DRIVERS\ACPI.sys
  0x01000000 \SystemRoot\system32\DRIVERS\msisadrv.sys
  0x0100A000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
  0x00F3D000 \SystemRoot\system32\DRIVERS\pci.sys
  0x01017000 \SystemRoot\System32\drivers\partmgr.sys
  0x0102C000 \SystemRoot\system32\DRIVERS\volmgr.sys
  0x00F70000 \SystemRoot\System32\drivers\volmgrx.sys
  0x01041000 \SystemRoot\system32\DRIVERS\pciide.sys
  0x00FCC000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
  0x00FDC000 \SystemRoot\System32\drivers\mountmgr.sys
  0x00FF6000 \SystemRoot\system32\DRIVERS\atapi.sys
  0x00E00000 \SystemRoot\system32\DRIVERS\ataport.SYS
  0x00E2A000 \SystemRoot\system32\DRIVERS\amdxata.sys
  0x00E35000 \SystemRoot\system32\drivers\fltmgr.sys
  0x00D9D000 \SystemRoot\system32\drivers\fileinfo.sys
  0x01208000 \SystemRoot\System32\Drivers\Ntfs.sys
  0x00C00000 \SystemRoot\System32\Drivers\msrpc.sys
  0x013AB000 \SystemRoot\System32\Drivers\ksecdd.sys
  0x014BC000 \SystemRoot\System32\Drivers\cng.sys
  0x0152F000 \SystemRoot\System32\drivers\pcw.sys
  0x01540000 \SystemRoot\System32\Drivers\Fs_Rec.sys
  0x0160E000 \SystemRoot\system32\drivers\ndis.sys
  0x01700000 \SystemRoot\system32\drivers\NETIO.SYS
  0x01760000 \SystemRoot\System32\Drivers\ksecpkg.sys
  0x01801000 \SystemRoot\System32\drivers\tcpip.sys
  0x0178B000 \SystemRoot\System32\drivers\fwpkclnt.sys
  0x0154A000 \SystemRoot\system32\DRIVERS\volsnap.sys
  0x017D5000 \SystemRoot\System32\Drivers\spldr.sys
  0x01596000 \SystemRoot\System32\drivers\rdyboost.sys
  0x017DD000 \SystemRoot\System32\Drivers\mup.sys
  0x017EF000 \SystemRoot\System32\drivers\hwpolicy.sys
  0x01400000 \SystemRoot\System32\DRIVERS\fvevol.sys
  0x0143A000 \SystemRoot\system32\DRIVERS\disk.sys
  0x01450000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
  0x015D0000 \SystemRoot\system32\DRIVERS\cdrom.sys
  0x014A8000 \SystemRoot\System32\Drivers\Null.SYS
  0x017F8000 \SystemRoot\System32\Drivers\Beep.SYS
  0x013C5000 \SystemRoot\System32\drivers\vga.sys
  0x013D3000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
  0x00DB1000 \SystemRoot\System32\drivers\watchdog.sys
  0x014B1000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
  0x00E81000 \SystemRoot\system32\drivers\rdpencdd.sys
  0x00DC1000 \SystemRoot\system32\drivers\rdprefmp.sys
  0x00DCA000 \SystemRoot\System32\Drivers\Msfs.SYS
  0x00DD5000 \SystemRoot\System32\Drivers\Npfs.SYS
  0x02CDC000 \SystemRoot\system32\DRIVERS\tdx.sys
  0x02CFA000 \SystemRoot\system32\DRIVERS\TDI.SYS
  0x02D07000 \SystemRoot\System32\Drivers\aswTdi.SYS
  0x02D17000 \SystemRoot\system32\drivers\afd.sys
  0x02DA1000 \SystemRoot\System32\Drivers\aswRdr.SYS
  0x02DAB000 \SystemRoot\System32\DRIVERS\netbt.sys
  0x02DF0000 \SystemRoot\system32\DRIVERS\wfplwf.sys
  0x02C00000 \SystemRoot\system32\DRIVERS\pacer.sys
  0x02C26000 \SystemRoot\system32\DRIVERS\vwififlt.sys
  0x02C3C000 \SystemRoot\system32\DRIVERS\netbios.sys
  0x02C4B000 \SystemRoot\system32\DRIVERS\serial.sys
  0x02C68000 \SystemRoot\system32\DRIVERS\wanarp.sys
  0x02C83000 \SystemRoot\system32\DRIVERS\termdd.sys
  0x036DB000 \SystemRoot\system32\DRIVERS\rdbss.sys
  0x0372C000 \SystemRoot\system32\drivers\nsiproxy.sys
  0x03738000 \SystemRoot\system32\DRIVERS\mssmbios.sys
  0x03743000 \SystemRoot\System32\drivers\discache.sys
  0x03752000 \SystemRoot\System32\Drivers\dfsc.sys
  0x03770000 \SystemRoot\system32\DRIVERS\blbdrive.sys
  0x03781000 \SystemRoot\System32\Drivers\aswSP.SYS
  0x037CA000 \SystemRoot\system32\DRIVERS\tunnel.sys
  0x03600000 \SystemRoot\system32\DRIVERS\amdppm.sys
  0x03615000 \SystemRoot\system32\DRIVERS\atikmpag.sys
  0x03A03000 \SystemRoot\system32\DRIVERS\atikmdag.sys
  0x0428F000 \SystemRoot\System32\drivers\dxgkrnl.sys
  0x04383000 \SystemRoot\System32\drivers\dxgmms1.sys
  0x043C9000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
  0x04200000 \SystemRoot\system32\DRIVERS\Rt64win7.sys
  0x04232000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
  0x0423F000 \SystemRoot\system32\DRIVERS\usbohci.sys
  0x03660000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
  0x0424A000 \SystemRoot\system32\DRIVERS\usbehci.sys
  0x0425B000 \SystemRoot\system32\DRIVERS\parport.sys
  0x04278000 \SystemRoot\system32\DRIVERS\ASACPI.sys
  0x04280000 \SystemRoot\system32\DRIVERS\serenum.sys
  0x04409000 \SystemRoot\system32\drivers\P17.sys
  0x0458E000 \SystemRoot\system32\drivers\portcls.sys
  0x045CB000 \SystemRoot\system32\drivers\drmk.sys
  0x02C97000 \SystemRoot\system32\drivers\ks.sys
  0x045ED000 \SystemRoot\system32\drivers\ksthunk.sys
  0x045F3000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
  0x043ED000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
  0x045FC000 \SystemRoot\system32\DRIVERS\vhidmini.sys
  0x041D9000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
  0x04400000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
  0x036B6000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
  0x048E5000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
  0x04909000 \SystemRoot\system32\DRIVERS\ndistapi.sys
  0x04915000 \SystemRoot\system32\DRIVERS\ndiswan.sys
  0x04944000 \SystemRoot\system32\DRIVERS\raspppoe.sys
  0x0495F000 \SystemRoot\system32\DRIVERS\raspptp.sys
  0x04980000 \SystemRoot\system32\DRIVERS\rassstp.sys
  0x0499A000 \SystemRoot\system32\DRIVERS\hamachi.sys
  0x049A5000 \SystemRoot\system32\DRIVERS\kbdclass.sys
  0x049B4000 \SystemRoot\system32\DRIVERS\mouclass.sys
  0x049C3000 \SystemRoot\system32\DRIVERS\mcdbus.sys
  0x04800000 \SystemRoot\system32\DRIVERS\swenum.sys
  0x04802000 \SystemRoot\system32\DRIVERS\umbus.sys
  0x04814000 \SystemRoot\system32\DRIVERS\usbhub.sys
  0x0486E000 \SystemRoot\System32\Drivers\NDProxy.SYS
  0x04890000 \SystemRoot\system32\drivers\AtihdW76.sys
  0x05655000 \SystemRoot\system32\drivers\viahduaa.sys
  0x00040000 \SystemRoot\System32\win32k.sys
  0x057E6000 \SystemRoot\System32\drivers\Dxapi.sys
  0x05600000 \SystemRoot\system32\DRIVERS\cdfs.sys
  0x0561D000 \SystemRoot\system32\DRIVERS\hidusb.sys
  0x0562B000 \SystemRoot\system32\DRIVERS\USBD.SYS
  0x0562D000 \SystemRoot\system32\DRIVERS\mouhid.sys
  0x048BD000 \SystemRoot\system32\DRIVERS\usbccgp.sys
  0x0563A000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
  0x057F2000 \SystemRoot\system32\DRIVERS\kbdhid.sys
  0x041F2000 \SystemRoot\System32\Drivers\crashdmp.sys
  0x04883000 \SystemRoot\System32\Drivers\dump_dumpata.sys
  0x048B0000 \SystemRoot\System32\Drivers\dump_atapi.sys
  0x01480000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
  0x048DA000 \SystemRoot\system32\drivers\LVUSBS64.sys
  0x05A11000 \SystemRoot\system32\drivers\usbaudio.sys
  0x05A2C000 \SystemRoot\system32\DRIVERS\monitor.sys
  0x004E0000 \SystemRoot\System32\TSDDD.dll
  0x007A0000 \SystemRoot\System32\cdd.dll
  0x05A3A000 \SystemRoot\system32\drivers\luafv.sys
  0x05A5D000 \??\C:\Windows\system32\drivers\aswMonFlt.sys
  0x05A97000 \SystemRoot\System32\Drivers\aswFsBlk.SYS
  0x05AA0000 \SystemRoot\system32\drivers\WudfPf.sys
  0x05AC1000 \SystemRoot\system32\DRIVERS\lltdio.sys
  0x05AD6000 \SystemRoot\system32\DRIVERS\nwifi.sys
  0x05B29000 \SystemRoot\system32\DRIVERS\ndisuio.sys
  0x05B3C000 \SystemRoot\system32\DRIVERS\rspndr.sys
  0x060EA000 \SystemRoot\system32\drivers\HTTP.sys
  0x061B2000 \SystemRoot\system32\DRIVERS\bowser.sys
  0x061D0000 \SystemRoot\System32\drivers\mpsdrv.sys
  0x06000000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
  0x0602D000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
  0x0607B000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
  0x05B54000 \SystemRoot\system32\drivers\peauth.sys
  0x0609E000 \SystemRoot\System32\Drivers\secdrv.SYS
  0x060A9000 \SystemRoot\System32\DRIVERS\srvnet.sys
  0x060D6000 \SystemRoot\System32\drivers\tcpipreg.sys
  0x06EA6000 \SystemRoot\System32\DRIVERS\srv2.sys
  0x06F0D000 \SystemRoot\System32\DRIVERS\srv.sys
  0x06FA3000 \SystemRoot\system32\DRIVERS\WUDFRd.sys
  0x06E71000 \SystemRoot\system32\DRIVERS\asyncmac.sys
  0x77590000 \Windows\System32\ntdll.dll
  0x47620000 \Windows\System32\smss.exe
  0xFF8B0000 \Windows\System32\apisetschema.dll
  0xFFF70000 \Windows\System32\autochk.exe
  0xFF6C0000 \Windows\System32\setupapi.dll
  0xFF650000 \Windows\System32\gdi32.dll
  0xFF5B0000 \Windows\System32\msvcrt.dll
  0xFF5A0000 \Windows\System32\nsi.dll
  0xFF580000 \Windows\System32\imagehlp.dll
  0xFF4A0000 \Windows\System32\advapi32.dll
  0xFF420000 \Windows\System32\shlwapi.dll
  0xFF210000 \Windows\System32\ole32.dll
  0xFF1F0000 \Windows\System32\sechost.dll
  0x77760000 \Windows\System32\normaliz.dll
  0xFF1A0000 \Windows\System32\ws2_32.dll
  0x77490000 \Windows\System32\user32.dll
  0xFE410000 \Windows\System32\shell32.dll
  0xFE3C0000 \Windows\System32\Wldap32.dll
  0xFE2E0000 \Windows\System32\oleaut32.dll
  0xFE260000 \Windows\System32\difxapi.dll
  0xFE190000 \Windows\System32\usp10.dll
  0xFE0F0000 \Windows\System32\comdlg32.dll
  0xFDFE0000 \Windows\System32\msctf.dll
  0x77370000 \Windows\System32\kernel32.dll
  0xFDEB0000 \Windows\System32\wininet.dll
  0xFDD80000 \Windows\System32\rpcrt4.dll
  0x77750000 \Windows\System32\psapi.dll
  0xFDCE0000 \Windows\System32\clbcatq.dll
  0xFDCD0000 \Windows\System32\lpk.dll
  0xFDA70000 \Windows\System32\iertutil.dll
  0xFDA40000 \Windows\System32\imm32.dll
  0xFD8C0000 \Windows\System32\urlmon.dll
  0xFD880000 \Windows\System32\cfgmgr32.dll
  0xFD840000 \Windows\System32\wintrust.dll
  0xFD6D0000 \Windows\System32\crypt32.dll
  0xFD6B0000 \Windows\System32\devobj.dll
  0xFD640000 \Windows\System32\KernelBase.dll
  0xFD5A0000 \Windows\System32\comctl32.dll
  0xFD590000 \Windows\System32\msasn1.dll
  0x75390000 \Windows\SysWOW64\normaliz.dll

Processes (total 70):
       0 System Idle Process
       4 System
     276 C:\Windows\System32\smss.exe
     376 csrss.exe
     448 C:\Windows\System32\wininit.exe
     456 csrss.exe
     512 C:\Windows\System32\services.exe
     532 C:\Windows\System32\lsass.exe
     540 C:\Windows\System32\lsm.exe
     556 C:\Windows\System32\winlogon.exe
     680 C:\Windows\System32\svchost.exe
     760 C:\Windows\System32\svchost.exe
     812 C:\Windows\System32\atiesrxx.exe
     900 C:\Windows\System32\svchost.exe
     960 C:\Windows\System32\svchost.exe
    1012 C:\Windows\System32\svchost.exe
     352 C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
    1008 C:\Windows\System32\svchost.exe
     304 C:\Windows\System32\atieclxx.exe
    1144 C:\Windows\System32\svchost.exe
    1280 C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    1568 C:\Windows\System32\spoolsv.exe
    1632 C:\Windows\System32\svchost.exe
    1712 C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    1748 C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    1820 C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
    1956 C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    2016 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    1112 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
    2032 C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
    2208 C:\Windows\System32\taskhost.exe
    2324 C:\Windows\System32\dwm.exe
    2360 C:\Windows\explorer.exe
    2624 C:\Program Files (x86)\Steam\Steam.exe
    2632 C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe
    2640 C:\Program Files (x86)\Skype\Phone\Skype.exe
    2648 C:\Program Files (x86)\ManyCam\Bin\ManyCam.exe
    2656 C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
    2672 C:\Program Files (x86)\MagicDisc\MagicDisc.exe
    2724 C:\Users\Michael\AppData\Local\Google\Update\1.2.183.39\GoogleCrashHandler.exe
    2780 C:\Windows\SysWOW64\rundll32.exe
    2860 C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
    2872 C:\Program Files (x86)\n52te\n52teHid.exe
    2880 C:\Program Files\Alwil Software\Avast5\AvastUI.exe
    2904 C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    2940 C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
    2976 C:\Program Files (x86)\iTunes\iTunesHelper.exe
    3044 C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    2720 C:\Windows\System32\svchost.exe
    3256 WUDFHost.exe
    3872 C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    3888 C:\Program Files\iPod\bin\iPodService.exe
    4020 C:\Windows\System32\svchost.exe
    3388 C:\Windows\System32\SearchIndexer.exe
    4164 C:\Program Files\Windows Media Player\wmpnetwk.exe
    4312 C:\Program Files (x86)\DisplayFusion\DisplayFusionHookx86.exe
    4752 C:\Windows\System32\svchost.exe
    4976 C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
    4792 dllhost.exe
    1920 C:\Windows\System32\svchost.exe
    2044 C:\Users\Michael\AppData\Local\Google\Chrome\Application\chrome.exe
     608 C:\Users\Michael\AppData\Local\Google\Chrome\Application\chrome.exe
    1644 C:\Users\Michael\AppData\Local\Google\Chrome\Application\chrome.exe
    3348 C:\Users\Michael\AppData\Local\Google\Chrome\Application\chrome.exe
    2556 C:\Windows\System32\audiodg.exe
    3312 C:\Windows\System32\SearchProtocolHost.exe
    2112 C:\Windows\System32\SearchFilterHost.exe
    3636 C:\Windows\System32\dllhost.exe
    3444 C:\Users\Michael\Desktop\MBRCheck.exe
    3456 C:\Windows\System32\conhost.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`06500000  (NTFS)

PhysicalDrive0 Model Number: HitachiHDS721010CLA332, Rev: JP4OA39C

      Size  Device Name          MBR Status
  --------------------------------------------
    931 GB  \\.\PhysicalDrive0   Known-bad MBR code detected (Whistler / Black Internet)!
            SHA1: 680C3DFB3AF5C02B7E098CA7B25CA73D63745DC5


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
Options:
  [1] Dump the MBR of a physical disk to file.
  [2] Restore the MBR of a physical disk with a standard boot code.
  [3] Exit.

Enter your choice: Enter the physical disk number to fix (0-99, -1 to cancel): 0Available MBR codes:
 [ 0] Default (Windows 7)
 [ 1] Windows XP
 [ 2] Windows Server 2003
 [ 3] Windows Vista
 [ 4] Windows 2008
 [ 5] Windows 7
 [-1] Cancel

Please select the MBR code to write to this drive: 0
Do you want to fix the MBR code?  Type 'YES' and hit ENTER to continue: yes
Successfully wrote new MBR code!
Please reboot your computer to complete the fix.


Done!
« Last Edit: January 17, 2011, 08:00:21 AM by Littledude »

You made me want to do a full scan lol

Also, I have rebooted my computer as suggested.

see if malwarebytes can do anything
i have avast and malwarebytes and i find that avast is good for general stuff, but MWB can actually find more things sometimes if i have infection(s)

see if malwarebytes can do anything
i have avast and malwarebytes and i find that avast is good for general stuff, but MWB can actually find more things sometimes if i have infection(s)
I've been running a full scan with this for the past 30 minutes so far nothing, it's been going through the steam folder for so long.


Download CCleaner, clean computer (Includeing Regestry). Maybe that is why your computer is slow. You have so much crap on there.

Time for a format?
I'm saving this for the absolute last course of action, I'd hate to lose all my stuff.

Run Microsoft Security Essentials. It's free and works like a charm.

I'm saving this for the absolute last course of action, I'd hate to lose all my stuff.

Yay for backups! Really, do them.