{"id":234,"date":"2009-12-22T18:50:47","date_gmt":"2009-12-23T01:50:47","guid":{"rendered":"http:\/\/daryllafferty.com\/blog\/2009\/12\/22\/mbr-virus\/"},"modified":"2010-04-12T08:59:30","modified_gmt":"2010-04-12T15:59:30","slug":"mbr-virus","status":"publish","type":"post","link":"https:\/\/daryllafferty.com\/blog\/2009\/12\/22\/mbr-virus\/","title":{"rendered":"MBR Virus"},"content":{"rendered":"<p>I was fixing a computer a few days ago that was driving me crazy.  When I began, it was full of malware; trojans, fake virus scanners and browser hijackers.  I ran the usual scanner\/cleaners and it seemed to be clean, but as soon as I started browsing it hijacked me to some malicious Russian website.  Of course, that immediately downloaded new trojans, and I was back where I started.<\/p>\n<p>I cleaned it again, using all the high-powered scanners I could find.  Clean&#8230; until I started browsing again, and poof! I was in Russia.<\/p>\n<p>I struggled with it for several hours, using esoteric process monitors, registry cleaners, etc., but I couldn&#8217;t find anything.  Then I happened to stumble on a web forum where someone described the same problem, and had an explanation and solution.<\/p>\n<p>It turned out to be a Master Boot Record (MBR) infection.  That&#8217;s normally outside the operating system control, and not anyplace most scanners will check.  MBR viruses used to be common with DOS and early Windows, but you don&#8217;t see them much anymore because Windows does a pretty good job of protecting the data there.  However, it can happen and may be on the increase, as it can escape most scanners.<\/p>\n<p>It&#8217;s easy to fix, once you know where it is (boot to the Recovery console and run fixmbr).  Next time I&#8217;ll know what to look for!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I was fixing a computer a few days ago that was driving me crazy. When I began, it was full of malware; trojans, fake virus scanners and browser hijackers. I ran the usual scanner\/cleaners and it seemed to be clean, but as soon as I started browsing it hijacked me to some malicious Russian website. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-234","post","type-post","status-publish","format-standard","hentry","category-computers"],"_links":{"self":[{"href":"https:\/\/daryllafferty.com\/blog\/wp-json\/wp\/v2\/posts\/234","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/daryllafferty.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/daryllafferty.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/daryllafferty.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/daryllafferty.com\/blog\/wp-json\/wp\/v2\/comments?post=234"}],"version-history":[{"count":0,"href":"https:\/\/daryllafferty.com\/blog\/wp-json\/wp\/v2\/posts\/234\/revisions"}],"wp:attachment":[{"href":"https:\/\/daryllafferty.com\/blog\/wp-json\/wp\/v2\/media?parent=234"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/daryllafferty.com\/blog\/wp-json\/wp\/v2\/categories?post=234"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/daryllafferty.com\/blog\/wp-json\/wp\/v2\/tags?post=234"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}