Hi

I have the same problem as tsahima, i just got to the last step of your instructions and now get this log when running mbr.exe from the windows folder

Stealth MBR rootkit detector 0.2.4 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully

however i'm lost as to what this means etc as i'm not the most computer savy person!

Dani AI

Generated

Quick summary for : the MBR tool you ran simply shows the utility was able to open the disk and read the Master Boot Record from both user and kernel contexts. That means the tool executed correctly — it does not by itself prove infection or safety. A clean MBR result will normally show matching user and kernel MBRs and no lines about “malicious code” or a “copy of MBR” in another sector; if your mbr.log contains only read-success messages and nothing flagged as malicious, that’s a good sign but not a full guarantee. (techlogon.com)

Context on psw.sinowal.c.boot: that name is tied to the Sinowal/TDSS family — an MBR/bootkit class of malware that historically infected the Master Boot Record or other disk sectors, hooked low-level device objects, and hid its presence. These bootkits often store a secondary copy of their code in a nonstandard sector, so a detector may report a “copy of MBR” elsewhere when one is present. Because they run below Windows, detection and cleanup usually require specialized, up-to-date tools or an offline scan. (helpnetsecurity.com)

Practical next steps: attach the full mbr.log (the file the tool creates) and a fresh HijackThis/log as requested so helpers can see the details. Before attempting repairs, back up personal files and, if possible, scan from a rescue environment or current vendor removal tool (examples: modern vendor removal utilities and offline scanners). If a bootkit is found and removed you may need to repair the boot record (for example with Windows Recovery commands such as bootrec /fixmbr or equivalent vendor tools) or, when removal is uncertain, image your data and do a clean reinstall. Follow vendor documentation when repairing boot records. (usa.kaspersky.com)

A note about ’s ComboFix suggestion: historically that tool was widely used but it is powerful and should only be run under experienced supervision — misuse (or contaminated downloads) has caused problems. Post the logs here and an experienced helper can recommend the safest, current toolset for removal. (community.avast.com)

Please download ComboFix by sUBs from or HERE

  • You must download it to and run it from your Desktop
  • Physically disconnect from the internet.
  • Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log
  • Re-enable all the programs that were disabled during the running of ComboFix..

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.