Help with Whistler@mbr [Rtk]

Hello,

I have been searching for ways of removing this threat from my system and have not had much luck. Like in other posts i have downloaded and run MBRcheck, and this did not fix it. I just now downloaded and ran OTL a few times, but i’m pretty out of my league working with this stuff.

I have the logs from those programs.

Any help would be appreciated.

Could you run MBRCheck once more for me please and post the log. Just a scan - not a repair

Here you go.

OK lets use windows to do this, 7 makes it easy

You must start Windows RE. To do this, follow these steps:

Put the Windows 7 installation disc in the disc drive, and then start the computer.
Press a key when you are prompted.
Select a language, a time, a currency, a keyboard or an input method, and then click Next.
Click Repair your computer.
Click the operating system that you want to repair, and then click Next.
In the System Recovery Options dialog box, click Command Prompt.
Type BootRec.exe /fixmbr
Press ENTER
When it has done its thing type exit and reboot

I’ll give that a try once I’m done work and I’m home, 5 more hours to go, this wait is going to kill me. BTW thanks for your help.

The good thing is once the recovery console is installed on 7 it is there all the time if you need it

Unfortunately this did not fix the problem, Whistler is still holding on strong to my MBR. I ran a scan with Avast and MBRcheck and it still shows it’s in there. Might there be something else we can try.

Just running through the various bootrec commands here http://support.microsoft.com/kb/927392 I will see if I can find an appropriate one for you

Hey Essexboy, thanks for trying to help he with this, but i think i’m just going to nuke and pave my disk. Do you think that would get rid of the virus if i were to do that. I would think so, but that is one tenacious little sucker.

Yes reformat the drive totally and do a clean install

If you wish you can give Avasts new MBR programme a trial spin before you reformat - if it works it may save you having to do that

Do you mean the aswMBR.exe software, I gave that a try already when i saw how to disable the driver signing enforcement, but it did not detect the virus unfortunately. I noticed someone mention a particular tool that would allow to rewrite the MBR, it’s called Testdisk and it’s a open source utility. I might give that a try first and if all else fails, nuke the sucker

Yep lets know if test disk works as it look like I might need some better tools with this miscreant

I’m rebooting now after writing the testdisk MBR, so let’s hope it comes back, (I’m connected remotly to my system from work).

I find that i’m really not able to keep track of which tool is reporting which disk is which.

It’s not coming back online, so it’s probably stuck in the boot menu, more waiting to come.

OK I will download and play with the tool myself now

Well i managed to muck up my system playing with tools i know nothing about, but my system is running smooth now after the reinstall :slight_smile:

Thanks for trying to help with all of this Essex, it’s much appreciated.

No problem - looking at test disc that is some powerfull tool with no real recovery option. So I do not think I will be using it ;D