Please Help. Trojan on MBR after reformat

fraziertom

Honorable
Oct 16, 2013
3
0
10,510
I'm so frustrated please help. Been working on my sister in laws WinVista computer for days. Her sons computer was badly infected with malware and trojans.

I did a clean install of rKill, AdwCleaner, ComboFix, RootRepeal, CCleaner Malwarebytes, Spybot S&D and the full trial version of AVG. I ran multiple scans in safe mode and regular startup until no more malicious software was fund.

Pryor to, after and during the scanning process I was also frequently getting the BSOD. Sometimes the BSOD would pop up on startup and sometimes durring a scan or after a scan, while updting windows or when accessing windows explorer. I decided to do a full system hardware scan and everything passed.

After believing that I now had a clean system I continued to get the BSOD. Disgusted, I figured that there must be some corrupt files on the system and I decided to reformat and reinstall Win-Vista from their Dell reinstall disk.

After formatting the drive, installing the Win Vista SP1, the drivers and doing Windows Update several times. I suddenly got a pop up from Microsoft Malicious Software Removal Tool saying that malicious software was detected. I first thought that it was a false positive since I reformatted the drive but, I did a further scan with MMSRT and found out that I have the Tojan: win64/alreon.gen!a Apparently this trojan corrupts the master boot record and it was NEVER detected by any of the previous scans prior to the reformat.

I was under the impression that when you reformat it also formats the MBR?

Anyway, that's where I'm at and not sure how to proceed. I think it would be simpler to reformat and reinstall again if I could reformat the MBR instead of trying to get rid of the trojan some other way through more scans.

Thanks for any help.
Tom
 
Solution
tom you need to do an fdiskl/mbr to delete the drives master boot record to remove the virus. then do an fdisk and remove all of the partion just to be sure there nothing left. there are tool disk like hirem boot cd. to boot and use old dos tools with the dell install disk if you can get to dos windows by using f key within the installer disk you should be able to run the fdisk command.
tom you need to do an fdiskl/mbr to delete the drives master boot record to remove the virus. then do an fdisk and remove all of the partion just to be sure there nothing left. there are tool disk like hirem boot cd. to boot and use old dos tools with the dell install disk if you can get to dos windows by using f key within the installer disk you should be able to run the fdisk command.
 
Solution

Primenay13

Honorable
Oct 16, 2013
31
0
10,540
In theory, doing a format doesn't delete data. It just deletes the partition table. I would at this point do a low level format of your drive. Do you know what brand of Hard drive you have? Seagate, WD, etc?
 

fraziertom

Honorable
Oct 16, 2013
3
0
10,510