Thursday, August 22, 2013

Non-booting Rootkit Infection FIXED

I had a client bring their non-booting Windows 7 PC to our shop in Kearny Mesa. Through our diagnostic process, we discovered a particularly nasty rootkit was to blame. Attaching the drive as a secondary to another PC and scanning it did not work in this instance. Multiple antivirus/rookit tools found the infection, but were unable to properly remove it. Hirens Boot CD to the rescue!

In this circumstance, the best option was to overwrite the MBR where the infection was hidden. This can be done using a very labor intensive command prompt method or Hiren's Boot CD includes a tool called MBR Work. This program includes the standard Windows 7 MBR files and in short order I was back in Windows!


**If you are unfamiliar with Hirens Boot CD or changing your MBR - Have your technician do this!**


Here's the steps :
1) Boot into the Hirens Boot CD (Version 13 and above)


2) Select Master Boot Record Tools (Option 1 on the version I used)


3) Select MBR Work utility


4) Select option 5 for Installing standard MBR Code


5) Select Windows 7 (The alternative option is for Windows XP)

6) Select "E" option for Exit. Restart PC.


Happy troubleshooting!


Greg -- Mobile Computer Wizard -- San Diego -- 619-255-1215 Office

1 comment: