Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


MBRoot/Sinowal@MBR code has been found

  • Please log in to reply
1 reply to this topic

#1 Carl999


  • Members
  • 17 posts
  • Local time:01:08 PM

Posted 01 August 2011 - 08:31 PM

Hello All,
This is my first post so I hope this is correct area to post.
I had W32/Blaster.worm that I managed to remove via rkill.
I ran GMER and amongst numerous entries the last four lines (with the last line in red) stating:

Disk \Device\Harddisk0\DRO Sector 00: rootkit like behaviour
Disk \Device\Harddisk0\DRO Malicious Win32:MBRoot code @ sector 312560643
Disk \Device\Harddisk0\DRO PE file @ sector 312560665
Disk \Device\Harddisk0\DRO MBRoot/Sinowal@MBR Code has been found

I don't like the look of the hard disk reference.
Can someone shed some light on what I should do. All I have done since finding this was run Malwarebytes Anti-Malware as "Defender" had installed itself on my system
and Anti-Malware so far has found 17 Objects Infected.
Thanks in advance..

BC AdBot (Login to Remove)


#2 Broni


    The Coolest BC Computer

  • BC Advisor
  • 42,725 posts
  • Gender:Male
  • Location:Daly City, CA
  • Local time:08:08 PM

Posted 01 August 2011 - 08:42 PM

Welcome aboard Posted Image

With the information you have provided I believe you will need help from the malware removal team.
Please make sure that you read the information about getting started first.
Then start a new thread HERE and include or required logs.
Including a link to this thread will be helpful.

Good luck and be patient. Help is on the way!

My Website


My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users