Please help. Trojan on MBR after reformat

TommyT

Weaksauce
Joined
Jan 24, 2002
Messages
92
I'm so frustrated please help. Been working on my sister in laws WinVista computer for days. Her sons computer was badly infected with malware and trojans.

I did a clean install of rKill, AdwCleaner, ComboFix, RootRepeal, CCleaner Malwarebytes, Spybot S&D and the full trial version of AVG. I ran multiple scans in safe mode and regular startup until no more malicious software was fund.

Pryor to, after and during the scanning process I was also frequently getting the BSOD. Sometimes the BSOD would pop up on startup and sometimes durring a scan or after a scan, while updting windows or when accessing windows explorer. I decided to do a full system hardware scan and everything passed.

After believing that I now had a clean system I continued to get the BSOD. Disgusted, I figured that there must be some corrupt files on the system and I decided to reformat and reinstall Win-Vista from their Dell reinstall disk.

After formatting the drive, installing the Win Vista SP1, the drivers and doing Windows Update several times. I suddenly got a pop up from Microsoft Malicious Software Removal Tool saying that malicious software was detected. I first thought that it was a false positive since I reformatted the drive but, I did a further scan with MMSRT and found out that I have the Tojan: win64/alreon.gen!a Apparently this trojan corrupts the master boot record and it was NEVER detected by any of the previous scans prior to the reformat.

I was under the impression that when you reformat it also formats the MBR?

Anyway, that's where I'm at and not sure how to proceed. I think it would be simpler to reformat and reinstall again if I could reformat the MBR instead of trying to get rid of the trojan some other way through more scans.

Thanks for any help.
Tom
 
As has been previously stated, if the malware is residing in the boot sector, you need fresh boot code to make everything work like normal. This thread may be of use as well.

I believe using the Windows Recovery tools on the operating system install disc will allow you to access the bootrec utility, which should also be capable of rewriting the boot sector with fresh code as detailed here.

Good luck.
 
Use a live distro to backup the stuff to an external disk, then boot off the windows install disk and run diskpart/clean from a command prompt, then proceed to install.
 
Thanks everyone. I will have a look at all the info tomorrow and have a go at it...
 
I suggest deleting the partition and starting from scratch, just remember to back up your files, may be a long and painful solution but will most likely solve your issue.
 
Then you will have to download Linux. The necessary tools are included with Windows. So I don't know if it is the best one.

Downloading linux is probably the best thing you can do in general. First step to broadening your vision and freeing up from MS slavery.
 
lol :)
Forgot to say that Boonies answer in post 2 is the easiest and quickest, it takes seconds to execute.
Run fdisk /mbr.
It can be done from a DOS boot disk or as he suggested.

Or if you have Linux tools handy, leeleatherwood' post #5 is just as good.
 
Use TDSSKiller and Malwarebytes Antirootkit and you will be fine. Also, if you are going to do a fixmbr, you must boot off the Vista/7/8 disk, open a command prompt and run bootrec /fixmbr. XP is straight fixmbr from the repair your computer section after you boot off an XP disk. This should help. (I do this stuff for a living and have become very good and removing infections.)
 
Back
Top